Impact
The vulnerability allows a low‑privileged attacker who can reach the Oracle Project Intelligence web interface over HTTP to create, delete, or modify critical data and read a subset of accessible data. This results in a breach of confidentiality and integrity for the affected database. The weakness stems from an improper access control mechanism, which is represented as CWE‑284.
Affected Systems
The flaw affects Oracle Corporation's Oracle Project Intelligence, part of Oracle E‑Business Suite, for supported releases ranging from 12.2.3 through 12.2.15. No other product versions are listed as susceptible.
Risk and Exploitability
The CVSS 3.1 base score of 7.1 indicates a moderate to high severity, with a low‑privileged attacker required and no user interaction. The EPSS score of less than 1% suggests exploitation probability remains low, and the vulnerability does not appear in the CISA KEV catalog. Nevertheless, because the flaw permits unauthorized data manipulation via a common network protocol, it poses a significant threat to systems exposed to networking.
OpenCVE Enrichment