Impact
A vulnerability in Oracle Financials for Asia/Pacific allows a low‑privileged attacker who can reach the system over HTTP to create, delete, or modify critical data and optionally read a subset of accessible data. The weakness leads to a loss of integrity for critical data and some loss of confidentiality. The flaw is rooted in improper access control that enables users with limited privileges to perform actions normally reserved for higher‑privileged roles. The potential impact is substantial, as attackers could alter transaction records or remove key data from the system, potentially disrupting business operations and financial reporting.
Affected Systems
This issue affects Oracle Financials for Asia/Pacific within Oracle E‑Business Suite’s Internal Operations component. Vendors listed identify Oracle Corporation as the provider. Affected releases are 12.2.3 through 12.2.15; any installation within those version ranges is susceptible. Future releases beyond 12.2.15 must be confirmed for the presence of the fix.
Risk and Exploitability
The CVSS score of 7.1 indicates a high risk level with a low confidentiality impact and a high integrity impact. The EPSS score 0.00318 indicates a 0.318% of exploitation, which is very low but not zero; however, the vulnerability is described as easily exploitable and requires only network access via HTTP, so the real‑world likelihood could still be significant for exposed installations. The vulnerability is not listed in CISA’s KEV catalog, so there is currently no known tracked exploitation. Attackers would need only basic network reconnaissance and standard HTTP access to leverage the flaw, making the threat realistic for organizations with insufficient network segmentation or weak access controls.
OpenCVE Enrichment