Impact
The vulnerability resides in the User Interface component of Oracle Customer Interaction History, part of Oracle E-Business Suite. It allows an attacker with low privileged credentials and network access over HTTPS to compromise the product, resulting in full takeover. The flaw is an improper access control issue; it permits unauthorized actions that can lead to loss of confidentiality, integrity and availability of the application.
Affected Systems
Oracle Corporation’s Oracle Customer Interaction History is affected. The vulnerability impacts supported versions 12.2.3 through 12.2.15 of the system. Systems running any of these releases of the product without the corresponding patch are vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates high severity, with direct effects on confidentiality, integrity and availability if exploited. The EPSS score of less than 1% suggests that current exploitation activity is limited, and the vulnerability is not listed in the CISA KEV catalog. Although the attack requires only a low privileged user account and network connectivity over HTTPS, the vulnerability is easily exploitable by a network-based attacker, making it a serious risk for organizations that have not applied the vendor’s fix.
OpenCVE Enrichment