Impact
The weakness resides in the Internal Operations component of Oracle Lease and Finance Management within Oracle E‑Business Suite. An attacker who can reach the application over HTTP can trigger the flaw and gain high‑level privileges, ultimately taking full control of the application. This enables compromise of confidentiality, integrity and availability, allowing the attacker to take over the system.
Affected Systems
Oracle Lease and Finance Management (Oracle E‑Business Suite) versions 12.2.7 through 12.2.15 are affected. The vulnerability is present in the component handling internal operations.
Risk and Exploitability
The CVSS v3.1 score of 7.2 indicates high severity. The EPSS score of less than 1% suggests a low current likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the flaw permits a high‑privileged attacker to gain full control, the potential impact is substantial. The likely attack vector is over the public network via HTTP, and an attacker would need network access to the vulnerable system to exploit the flaw.
OpenCVE Enrichment