Impact
Easily exploitable vulnerability in Oracle Spares Management within Oracle E‑Business Suite allows a low‑privileged attacker with network access via HTTP to compromise the application. Because the flaw grants significant confidentiality, integrity, and availability impact, an attacker can effectively take over the Oracle Spares Management component, achieving full control of the service and potentially impacting other parts of the E‑Business Suite. The vulnerability stems from an access control weakness, classified as CWE‑284.
Affected Systems
Oracle Spares Management in Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are affected. The Internal Operations component is the only part impacted by this vulnerability.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 indicates a high severity risk, with significant impacts to confidentiality, integrity, and availability. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is HTTP traffic to the Spares Management service from a low‑privileged user who can exploit insufficient access controls to achieve takeover. No additional access or privilege escalation requirements are mentioned beyond these conditions.
OpenCVE Enrichment