Impact
The Oracle Spares Management module of Oracle E‑Business Suite contains a vulnerability that allows an attacker with low privileges and network access over HTTP to compromise the application. The flaw enables the attacker to gain full control of the application, potentially exfiltrating data or disrupting services. The weakness manifests as improper access control (CWE-284).
Affected Systems
The affected product is Oracle Spares Management from Oracle Corporation, specifically the Internal Operations component of Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are affected, as identified by the vendor and the cpe:2.3:a:oracle:spares_management:*:*:*:*:*:*:* entry.
Risk and Exploitability
The vulnerability scored a CVSS base score of 8.8, signifying high severity. The EPSS score of less than 1% indicates that, at present, the likelihood of exploit in the wild is low, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only HTTP access and a low‑privileged attacker; thus an adversary on the network can potentially gain full control over the application, leading to data exfiltration or service disruption.
OpenCVE Enrichment