Impact
The Oracle Customer Interaction History component named Outcome‑Result contains a flaw that permits an attacker with low privileges to exploit the application over HTTP. The vulnerability allows unauthorized access that can lead to a complete takeover of the application, compromising confidentiality, integrity, and availability.
Affected Systems
Oracle Corporation’s Oracle Customer Interaction History, part of Oracle E‑Business Suite, is affected in releases 12.2.3 through 12.2.15. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS base score of 8.8 reflects high impact. EPSS less than 1% indicates rare current exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers require only low privileges and HTTP network access; no user interaction is needed, making the flaw remotely reachable when the component is exposed to the network.
OpenCVE Enrichment