Impact
Oracle Sales Online is vulnerable to an easily exploitable flaw that allows a low‑privileged attacker with network access via HTTP to compromise internal operations. The vulnerability requires human interaction from a person other than the attacker, and while it is confined to Sales Online it can change scope and potentially impact other products. Successful exploitation can grant the attacker unauthorized access to critical data and, in some cases, the ability to update, insert or delete accessible data, thereby compromising confidentiality and, to a lesser extent, integrity.
Affected Systems
The affected product is Oracle Sales Online within Oracle E‑Business Suite. Vulnerable versions are 12.2.3 through 12.2.15. No other vendors or products are listed, though the attack may influence additional Oracle applications due to scope change.
Risk and Exploitability
The base CVSS score is 7.6, indicating a high‑severity vulnerability with significant confidentiality impact but no availability impact. The EPSS score is less than 1%, suggesting a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over the network using HTTP, inferred from the description; the attacker requires low privileges and some form of human interaction from a person other than the attacker to trigger the exploit.
OpenCVE Enrichment