Impact
A low privileged attacker who can reach the system over HTTP can exploit a weakness in the Oracle Loans component of Oracle E‑Business Suite to gain unauthorized access to critical data and alter or delete it. The vulnerability can lead to data confidentiality breaches and integrity violations throughout the Oracle Loans application. It does not affect system availability.
Affected Systems
Oracle Loans, a component of Oracle E‑Business Suite, is affected in versions 12.2.3 through 12.2.15. The flaw resides in the Internal Operations area and is reachable via standard HTTP traffic.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high risk, especially given the low attack complexity and low privilege requirement. While the EPSS score is <1%, indicating a very low exploitation probability, the direct HTTP access vector suggests a readily exploitable route. The vulnerability is not listed in CISA’s KEV catalog at present, but it remains a significant threat to confidentiality and integrity for any organization running the affected Oracle Loans versions.
OpenCVE Enrichment