Impact
Oracle Loans, a component of Oracle E‑Business Suite, contains an improper privilege management flaw that allows a low‑privileged attacker with network access via HTTP to create, delete or modify critical data and to trigger a partial denial of service. The vulnerability enables unauthorized access to data without authentication and is classified as a CWE‑284 type weakness.
Affected Systems
Oracle Corporation’s Oracle Loans product is affected for every supported release from version 12.2.3 through 12.2.15 inclusive. Any deployment that runs one of these releases is vulnerable; versions outside this range are not known to be impacted.
Risk and Exploitability
The CVSS 3.1 Base Score of 7.1 signifies a moderate to high risk. Because no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, there is no documented public exploitation yet. The attack vector is inferred to be remote HTTP: an adversary can connect to the service over the network, bypass authentication checks, and manipulate data or trigger a partial denial of service using only the privileges granted by network access, with no additional privileges required.
OpenCVE Enrichment