Impact
A flaw in the Change Management component of Oracle Project Planning and Control allows a low‑privileged attacker with HTTP network access to create, delete, or modify critical data. This can result in confidentiality and integrity violations.
Affected Systems
The affected product is Oracle Project Planning and Control, part of Oracle E‑Business Suite, with impacted versions ranging from 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS v3.1 score of 8.1 indicates high severity, and the vector shows network access, low authentication, and no user interaction are required. The EPSS score is < 1%, indicating a very low exploitation probability, yet the combination of a predictable attack path and high impact implies a substantial risk that should be mitigated promptly.
OpenCVE Enrichment