Impact
Oracle Demand Planning is vulnerable to an unauthenticated HTTP-based attack that allows an attacker to read, update, insert, or delete data exposed by the application, driven by weaknesses in authentication and access control. This flaw provides unchecked access to critical supply‑chain information, resulting in confidentiality and integrity impacts as captured by a CVSS 3.1 Base Score of 8.2.
Affected Systems
The vulnerability affects Oracle Demand Planning released by Oracle Corporation, specifically versions 12.1 and 12.2. It is located within the internal operations component of the product and applies to any deployment that exposes the web interface to network traffic.
Risk and Exploitability
This flaw is highly exploitable because it requires no privileges, no user interaction, and low complexity. An adversary with network access to the HTTP interface can exploit it directly. The EPSS score is < 1% and the CVE is not listed in the CISA KEV catalog, yet the combination of high CVSS scoring and open exposure means that it should be treated with high urgency, especially for systems reachable from untrusted networks.
OpenCVE Enrichment