Impact
Vulnerability in Oracle Purchasing version 12.2.3–12.2.15 allows low‑privilege attackers with network access through the HTTP interface to fully compromise the application. The flaw is easily exploitable and bypasses normal authentication controls, enabling attackers to take over Oracle Purchasing with complete confidentiality, integrity, and availability loss.
Affected Systems
Oracle Purchasing versions 12.2.3 through 12.2.15 are affected. All installations of these releases that expose the HTTP interface to external networks are at risk.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 reflects high severity. The EPSS score is less than 1 %, suggesting a low current exploitation probability, but the lack of mitigations and the web‑based attack surface imply that the vulnerability remains a valuable target. The issue is not listed in CISA KEV, yet attacks can be launched from any host that can reach Oracle Purchasing over HTTP, making weaponization straightforward.
OpenCVE Enrichment