Impact
This vulnerability allows an attacker with low privileges and network access over HTTP to fully compromise the Oracle User Management component of Oracle E‑Business Suite. Once exploited, the attacker can gain control of the application, undermining the confidentiality, integrity, and availability of the system.
Affected Systems
It affects Oracle User Management in the Oracle E‑Business Suite, with supported affected versions ranging from 12.2.6 through 12.2.15.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 reflects a high severity, and an EPSS score of less than 1% indicates a very low yet nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be a network attack via HTTP, requiring only low privilege credentials or access rights to succeed.
OpenCVE Enrichment