Impact
This vulnerability arises in the Oracle Application Object Library component of Oracle E-Business Suite. An unauthenticated attacker with network access to HTTPS can compromise the library, enabling unauthorized creation, deletion, modification, or complete access to critical data. The flaw represents an improper authorization weakness that results in confidentiality and integrity impacts as reflected in the CVSS vector.
Affected Systems
Oracle Corporation’s Oracle Application Object Library, part of Oracle E-Business Suite Core, is affected in versions 12.2.3 through 12.2.15. Users of these releases are at risk if the vulnerable component remains unpatched.
Risk and Exploitability
The CVSS Base Score of 7.4 indicates high severity for confidentiality and integrity. The EPSS score of less than 1% and the vulnerability is not listed in CISA’s KEV catalog. Attackers must be able to reach the HTTPS interface of the library; no credentials are required. Because the vulnerability is described as difficult to exploit, successful attacks will grant the attacker significant data access but are unlikely to impact availability. The overall risk low in exploitation likelihood.
OpenCVE Enrichment