Impact
Oracle One-to-One Fulfillment of Oracle E-Business Suite contains a component‑level vulnerability that allows a low‑privileged attacker with HTTP network access to compromise the system. Successful exploitation gives the attacker unauthorized access to critical data or full access to all data available through the product, and can cause a partial denial of service. The flaw impacts confidentiality heavily and availability modestly, with no integrity effects as indicated by the CVSS vector.
Affected Systems
The affected product is Oracle One-to-One Fulfillment within Oracle E-Business Suite. Versions from 12.2.3 through 12.2.15 are vulnerable, as documented by Oracle.
Risk and Exploitability
The CVSS base score of 7.1 classifies the vulnerability as high impact, and the EPSS score of less than 1 percent suggests a low probability of exploitation at this time. However, the vulnerability is easily exploitable and can be leveraged by a low‑privileged network attacker without special credentials. The product is not listed in CISA KEV, but the confidentiality risk warrants proactive mitigation.
OpenCVE Enrichment