Impact
Easily exploitable vulnerability in Oracle Process Manufacturing Systems enables a low‑privileged attacker who can reach the system over HTTP to compromise the application. Successful exploitation allows the attacker to create, delete or modify critical data, or obtain full access to all data available through the system. This access control flaw (CWE-284) results in high confidentiality and integrity impact, as reflected by the CVSS 3.1 vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N.
Affected Systems
Oracle Process Manufacturing Systems, part of Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 conveys high severity. An EPSS score of 0.00298 (≈0.3%) indicates a very low estimated exploitation probability, and the vulnerability is not listed in CISA KEV, suggesting no known public exploitation. The attack vector is network via HTTP; low privileges are sufficient, and no user interaction is required. An attacker with internal or external network access could send crafted HTTP requests to the Internal Operations component, bypassing normal authorization controls.
OpenCVE Enrichment