Impact
The vulnerability resides in the Product Diagnostic Tools component of Oracle Order Management, part of Oracle E-Business Suite. A low-privileged attacker with network access via HTTP can exploit the flaw to compromise the application and eventually take control. The attacker can read, modify, and delete Order Management data and fully manipulate the instance, resulting in a complete takeover. This is reflected in the CVSS 3.1 score of 7.5, indicating high confidentiality, integrity, and availability impacts.
Affected Systems
Oracle Corporation’s Oracle Order Management product, versions 12.2.3 through 12.2.15, is affected. The flaw is confined to the Product Diagnostic Tools component of the suite. No other versions or components are identified as impacted.
Risk and Exploitability
The CVSS base score of 7.5 classifies the issue as high severity. The EPSS score is less than 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in CISA KEV. The attack vector appears to be network-based via HTTP; a low-privilege attacker with network access can exploit the flaw, making it realistic for adversaries that can reach the target. Successful attacks result in full application takeover, compromising confidentiality, integrity, and availability.
OpenCVE Enrichment