Impact
Oracle Internet Procurement Connector versions 12.2.3 through 12.2.15 contain a flaw in the HTTP interface that allows a low‑privileged attacker with network access to create, delete or modify critical data and retrieve all data handled by the connector. The vulnerability grants full data‑handling capabilities without proper authorization, leading to loss of confidentiality and integrity of the data processed by the application.
Affected Systems
The affected product is Oracle Corporation’s Internet Procurement Connector running within Oracle E‑Business Suite, specifically versions 12.2.3 to 12.2.15 inclusive. No other vendor or product version is listed as affected.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates a high severity score driven by significant confidentiality and integrity impacts. The EPSS score of <1% indicates a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is the exposed HTTP interface, and the attacker only needs low‑privileged network connectivity to exploit the flaw. The combination of a high CVSS score and realistic access requirements makes this a realistic threat for organizations that expose the Connector to internal or external networks.
OpenCVE Enrichment