Impact
A vulnerability in Oracle Marketing’s Audience component allows an attacker with low privileges and network access via HTTP to read and modify marketing data. The weakness stems from missing or incorrect application‑level authorization controls (CWE‑284). Successful exploitation can lead to confidential data exposure (high confidentiality impact) as well as unauthorized insert, update or delete operations, affecting data integrity.
Affected Systems
Oracle Corporation’s Oracle Marketing product, part of Oracle E‑Business Suite, is affected. Supported releases from version 12.2.3 through 12.2.15 are susceptible to this flaw. The vulnerability resides in the Audience component, and because the scope change may be broadened, other Oracle Marketing services on the same installation may also be impacted.
Risk and Exploitability
The CVSS 3.1 base score of 8.5 signifies a high severity assessment, while an EPSS score of less than 1% indicates a low current exploitation probability. The flaw is not listed in the CISA KEV catalog. Attackers need only low privileges over an HTTP connection, and a successful attack grants extensive read and write capabilities across all Oracle Marketing data. Despite the low exploitation likelihood, the potential for widespread data compromise warrants immediate remediation.
OpenCVE Enrichment