Impact
A flaw in Oracle CRM Technical Foundation enables a low‑privileged attacker who can reach the product’s HTTP interface to create, delete or modify critical data. The weakness is a missing or insufficient access control that permits users to carry out privileged operations. This flaw compromises the confidentiality and integrity of all data accessible through the CRM.
Affected Systems
Oracle Corporation’s Oracle CRM Technical Foundation, part of Oracle E‑Business Suite, is affected for versions 12.2.3 through 12.2.15. The vulnerability resides in the Application Framework component that processes HTTP requests for data manipulation.
Risk and Exploitability
The CVSS v3.1 Base Score of 8.1 indicates a high severity rating. The attack vector is network (AV:N) with low privileges (PR:L). The EPSS score of <1% suggests a low likelihood of exploitation in the wild at this time. The flaw is not listed in the CISA KEV catalog. An attacker with network access to the CRM’s HTTP interface can exploit the flaw to alter or delete data, jeopardizing business operations.
OpenCVE Enrichment