Impact
An easily exploitable flaw in the Oracle Financials for EMEA product of Oracle E‑Business Suite allows an attacker who is a low‑privileged user and has network reachability over HTTP to gain unauthorized access to critical data. The vulnerability can also allow the attacker to insert, update, or delete data that the user normally cannot reach, thereby undermining the integrity of the application’s data. The weakness results in confidentiality loss for sensitive records and potential manipulation of financial information.
Affected Systems
Oracle Corporation’s Oracle Financials for EMEA, part of the Oracle E‑Business Suite, internally scoped under the Internal Operations component. The affected releases span from version 12.2.3 through 12.2.15, meaning any installation of the product within this range is vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 7.1 indicates a high severity, with an attack vector over the network and low authentication required. The EPSS score of < 1% indicates a low, but non‑zero, probability of exploitation. Because the weakness is exploitable via a standard HTTP request, an attacker need only be able to reach the application, making it attractive in environments where this application is exposed to the internet or an untrusted internal network. The flaw is not currently listed in the CISA KEV catalog, but its impact and potential for compromise warrant immediate attention.
OpenCVE Enrichment