Impact
The vulnerability resides in the Internal Operations component of Oracle Financials for EMEA within Oracle E‑Business Suite. A low‑privilege attacker who can reach the application over HTTP can exploit the flaw to read sensitive data and to perform unauthorized insert, update, or delete operations on data accessible through Oracle Financials for EMEA. This results in confidentiality and integrity violations for the affected data set.
Affected Systems
All publicly reported releases of Oracle Financials for EMEA from version 12.2.3 through 12.2.15 are impacted. The issue applies to the Oracle E‑Business Suite deployment, specifically the Internal Operations module, and any environment that exposes the application’s HTTP endpoints to the network.
Risk and Exploitability
The CVSS v3.1 base score of 7.1 indicates a high risk to confidentiality and a lower, but still significant, impact on integrity. The attack can be carried out via direct HTTP connections to the affected application, requiring only low‑privilege credentials and network accessibility. Because the exploit does not require special or privileged user accounts, the probability of successful exploitation is high, even though an EPSS value is not available. The vulnerability is not yet listed in CISA’s KEV catalog, but the simplicity of the attack path warrants rapid mitigation.
OpenCVE Enrichment