Impact
A flaw in the Search Bean component of Oracle Applications Framework allows a low‑privileged attacker with network access via HTTP to gain unauthorized ability to create, delete, or modify critical data and to access all data exposed by the framework. The weakness, identified as CWE-284, stems from insecure permission handling that does not restrict these actions to privileged users. Successful exploitation can lead to significant confidentiality and integrity violations, potentially affecting all data accessible through the framework.
Affected Systems
Oracle Applications Framework version 12.2.3 through 12.2.15 are affected. These releases are part of Oracle E‑Business Suite and are supported for use by enterprise applications.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 indicates a high severity vulnerability. The EPSS score is reported as < 1 %, implying a low probability of exploitation at present, and it is not listed in the CISA KEV catalog. Nonetheless, the attack vector is network‑based via HTTP, and the low privileged attacker requirement means that anyone with network reach to the application, even with minimal credentials, can potentially exploit the flaw. An attacker who succeeds could alter or delete critical business data or gain full access to the framework’s data store.
OpenCVE Enrichment