Impact
A vulnerability in Oracle CRM Technical Foundation allows an attacker who can reach or modify data without proper authorization, compromising the confidentiality and integrity of critical information. The weakness arises from inadequate access control that permits low‑privileged users to perform privileged operations.
Affected Systems
Oracle Corporation’s Oracle CRM Technical Foundation, part of Oracle E‑Business Suite, is affected for versions 12.2.3 through 12.2.15. This includes the Application Framework component that handles data manipulation via HTTP endpoints.
Risk and Exploitability
The CVSS v3.1 Base Score of 8.1 indicates a high severity issue that can be exploited easily, with an attack vector of network and required privileges of low. The EPSS score of < 1% shows a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. An attacker with network access to the CRM’s HTTP interface can leverage the flaw to elevate their capabilities and permanently alter or delete data, impacting business operations.
OpenCVE Enrichment