Impact
The vulnerability is an improper access control flaw in Oracle MES for Process Manufacturing, part of Internal Operations. A low‑privileged attacker who can reach the system over HTTP can exploit insufficient permission checks and gain unauthorized read access to critical manufacturing data. This can lead to data leakage and potential further exploitation of the system.
Affected Systems
Oracle MES for Process Manufacturing, a component of Oracle E‑Business Suite (Internal Operations). Versions 12.2.3 through 12.2.15 are affected. The flaw may also impact other products due to a scope change, but MES remains the primary target.
Risk and Exploitability
The CVSS 3.1 base score of 7.7 reflects a high severity. The attack vector is network (HTTP), with low attack complexity and low privilege requirements. The vulnerability is exploitable remotely without user interaction. Because the EPSS score is less than 1 % and the vulnerability is not listed in CISA KEV, the likelihood of widespread exploitation appears low at present, but the potential impact on confidentiality is significant. The scope change creates the risk that success could lead to broader access to other components.
OpenCVE Enrichment