Impact
The vulnerability is a privilege escalation flaw that allows a low‑privileged attacker with network access via HTTP to the Internal Operations endpoint to compromise Oracle Quality. Successful exploitation can lead to a full takeover of the application, affecting confidentiality, integrity, and availability.
Affected Systems
Oracle Quality inside Oracle E‑Business Suite, versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS rating of 7.5 reflects high severity, but an EPSS score of less than 1 % indicates a low probability of widespread exploitation. The flaw can be triggered by a low‑privileged attacker who gains HTTP access to the Internal Operations endpoint of Oracle Quality, making it difficult to exploit in practice. The exploit does not elevate a critical concern for organizations running the affected versions. The vulnerability is not listed in CISA KEV.
OpenCVE Enrichment