Impact
The vulnerability in Oracle Spares Management allows an attacker with compromise of the application. The impact includes a loss of confidentiality, integrity, and availability, as the attacker can access, modify, or delete critical data. This is a high‑severity flaw, scored at 8.8 on CVSS 3.1, indicating a severe threat if exploited. Key weakness type is improper access control, allowing privileged escalation from a low‑privileged state.
Affected Systems
Oracle Corporation’s Oracle Spares Management product for Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, is affected. The security alert specifies that only these supported versions are vulnerable and that exploitation is possible via the internal operations component exposed to the network.
Risk and Exploitability
This flaw poses a serious risk to organizations that use the affected Oracle E‑Business Suite instances. The EPSS score of <1% indicates a very low current exploitation probability, but the high CVSS score of 8.8 shows significant potential impact if exploited. The vulnerability is not listed in CISA KEV catalog. It should be fully remediated as quickly as possible.
OpenCVE Enrichment