Impact
A vulnerability in Oracle Demand Planning allows a low privileged attacker with network access via HTTP to exploit the system and gain unauthorized ability to create, delete, or modify critical data, and to access all accessible data. The flaw can be leveraged without user interaction and results in high confidentiality and integrity impacts.
Affected Systems
The affected product is Oracle Demand Planning, versions 12.1 and 12.2, released by Oracle Corporation as part of the Oracle Supply Chain suite.
Risk and Exploitability
The CVSS v3.1 score of 9.6 indicates a very high level of risk. The vulnerability is easily exploitable (access vector network, low attack complexity, local privileges). The EPSS score is < 1%, indicating a very low estimated probability of exploitation in practice, but the lack of a KEV listing does not reduce the urgency, as the potential scope change could affect additional Oracle products.
OpenCVE Enrichment