Impact
A vulnerability in Oracle General Ledger’s Internal Operations component allows an attacker with low privileged network access via HTTP to create, delete or modify critical data, read sensitive data, and cause a partial denial of service. This results in confidentiality, integrity, and availability impacts.
Affected Systems
Oracle General Ledger versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity level. The exploitability involves network access to the application’s HTTP interface and low required privileges. This vulnerability is not listed in the CISA KEV catalog and its EPSS score of 0.00314 (0.3 %) indicates a very low probability of exploitation, but the combination of a high CVSS baseline and ease of exploitation suggests it poses a significant risk to organizations running the affected product.
OpenCVE Enrichment