Impact
The vulnerability in Oracle Spares Management allows an attacker who already possesses high privileges and has network access via HTTP to compromise the system. Successful exploitation can lead to a full takeover of Oracle Spares Management, resulting in confidentiality, integrity, and availability loss across the affected product. The impact may extend to other Oracle products that interact with it due to a scope change, underscoring the need for strict access controls and proper authentication verification.
Affected Systems
Affected versions are 12.2.3 through 12.2.15 of Oracle Spares Management, part of Oracle E‑Business Suite. The impact may extend beyond this component to other Oracle products that interact with it due to a scope change.
Risk and Exploitability
The CVSS 3.1 Base Score of 8.0 indicates high severity. The EPSS score is less than 1 %, suggesting a low probability of exploit at this time, and it is not listed in the CISA KEV catalog. Nevertheless, the remote attack vector via HTTP and the potential to affect other products means that the risk remains significant, especially for systems still running the affected versions.
OpenCVE Enrichment