Impact
Based on the description, the attack vector is HTTP. A vulnerability in the Internal Operations component of Oracle Process Manufacturing Systems allows a low privileged attacker who can reach the system over HTTP to compromise the application. Successful exploitation can lead to complete takeover of the system, exposing all data and control functions, and it has severe implications for confidentiality, integrity and availability. The weakness involves improper access control (CWE-284), as reflected in CVSS 3.1 scoring of 7.5, indicating that the issue is not trivial and can be fully leveraged once the attacker has network access.
Affected Systems
Oracle Process Manufacturing Systems versions 12.2.3 to 12.2.15 are affected. These are part of the Oracle E‑Business Suite and are deployed in manufacturing operations environments.
Risk and Exploitability
The vulnerability is accessed through a standard HTTP port, meaning it is exposed to anyone on the network who can reach the service. No known public exploit is listed, and the EPSS score of less than 1% indicates a very low probability of exploitation, but the CVSS Base Score of 7.5 demonstrates high potential impact if exploited. Because the attack requires only low privileges and network access, the risk to exposed systems remains significant. The vulnerability is not currently in the CISA KEV catalog, though its severity warrants immediate attention.
OpenCVE Enrichment