Impact
A low‑privileged attacker who can connect over HTTP can fully compromise the Oracle Sales Online application, gaining control of the system and its data. The flaw is an improper access control vulnerability (CWE-284) that permits unauthorized access to protected resources. The impact includes loss of confidentiality, integrity, and availability as the attacker can modify, delete, or read sensitive information and disrupt normal operation.
Affected Systems
Oracle Corporation’s Oracle Sales Online product of Oracle E‑Business Suite, versions 12.2.3 to 12.2.15, is affected.
Risk and Exploitability
The CVSS v3.1 base score is 8.8, reflecting high severity. The EPSS score is below 1%, indicating that exploitation is currently considered unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. Attack is likely over HTTP, requires only low privileged access, and the exploitation path is straightforward from the network.
OpenCVE Enrichment