Impact
The vulnerability in Oracle Sales Online allows a low‑privileged attacker who can reach the application via HTTP to gain unauthorized access to all accessible data and perform insert, update, or delete operations on that data. The impact includes confidentiality loss for critical data and integrity alteration through unauthorized data changes. The weakness is rooted in improper access control, as indicated by the CVE vector specifying a change in scope and the low privileged user being able to extend access beyond normal limits.
Affected Systems
Oracle Corporation’s Oracle Sales Online component of Oracle E‑Business Suite is affected. Supported product versions ranging from 12.2.3 through 12.2.15 are vulnerable, while later releases are presumed unaffected. Any deployment of these versions over the network remains at risk.
Risk and Exploitability
With a CVSS 3.1 Base Score of 8.5, the vulnerability is considered high severity. The EPSS score is reported as less than 1%, indicating a low probability of exploitation in the general population, but the lack of CISA KEV listing does not eliminate the risk to targeted environments. The attack vector is network‑based via HTTP, requiring only low privileged access, which makes exploitation relatively easy for adversaries with network reach to the application.
OpenCVE Enrichment