Impact
The vulnerability is an improperly enforced access control flaw in Oracle Product Hub, affecting the Outbound Data component, that allows a low‑privileged attacker with network access via HTTP to gain full control of the application. The CVSS 3.1 base score of 8.8 indicates severe confidentiality, integrity and availability impacts, and successful exploitation would result in a complete takeover of Oracle Product Hub.
Affected Systems
Oracle Product Hub, a component of Oracle E‑Business Suite, is impacted for supported versions from 12.2.3 through 12.2.15.
Risk and Exploitability
The attack vector is network‑based and requires only low privileges, making it highly exploitable from any location that can reach the HTTP service. The EPSS score of <1% indicates a very low probability of exploitation in the wild, but the high CVSS score and the ability to compromise the entire hub still present a critical risk for exposed deployments.
OpenCVE Enrichment