Impact
This vulnerability allows a low‑privileged attacker with network access to bypass authorization controls in Oracle Site Hub and perform unauthorized creation, deletion, modification, or read operations on critical data, thereby compromising both confidentiality and integrity (CWE‑284). The flaw is easily exploitable over HTTP, requires no user interaction, and can be carried out remotely.
Affected Systems
Affected product is Oracle Site Hub, component Internal Operations of Oracle E‑Business Suite. Versions from 12.2.3 through 12.2.15 are impacted. Customers running these releases without the vendor’s fix are subject to the risk described above.
Risk and Exploitability
The CVSS 3.1 score of 7.1 indicates moderate severity, while the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not listed in CISA KEV. The likely attack vector is network‑based via HTTP; the low privilege requirement and absence of UI interaction make the exploitation path straightforward and potentially automatable. Although exploitation is not widespread at present, the potential impact on confidential data warrants care and prompt remediation.
OpenCVE Enrichment