Impact
Oracle Alert in Oracle E‑Business Suite contains an easily exploitable flaw that allows a low‑privileged attacker with network access via HTTP to create, delete, or modify critical data. Successful exploitation can lead to unauthorized changes to the data stored in Oracle Alert, compromising both confidentiality and integrity. The CVSS vector reflects no availability impact but high confidentiality and integrity effects.
Affected Systems
The affected products are Oracle Alert for Oracle E‑Business Suite, supported versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates a high severity vulnerability. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not yet listed in CISA’s KEV catalog. The attack vector is network‑based over HTTP and requires the attacker to have low‑privileged credentials within the system, after which they can leverage improper access controls to gain unauthorized modification or deletion rights over Oracle Alert data.
OpenCVE Enrichment