Impact
A flaw in the Oracle Partner Management component of Oracle E‑Business Suite allows a low‑privileged attacker with network access over HTTP to bypass authentication controls and gain unauthorized read or write access to data that the application exposes. The weakness is an improper allocation of permissions, identified as CWE‑284, and results in confidentiality compromise and the possibility of altering or deleting critical records. The vulnerability does not directly affect application availability but enables an attacker to view or modify data that should be tightly controlled.
Affected Systems
Oracle Partner Management, a component of Oracle E‑Business Suite, is affected. Supported versions from 12.2.3 through 12.2.15 are potentially vulnerable.
Risk and Exploitability
The CVSS base score of 7.1 places the issue in the high‑severity range, while the EPSS score of < 1% indicates that exploitation attempts are currently expected to be rare. The vulnerability is not listed in the CISA KEV catalog. Attackers would most likely exploit this via unauthenticated HTTP traffic, and the scope of the weakness may extend to other products within the Oracle suite if access controls are similarly weak.
OpenCVE Enrichment