Impact
Vulnerability in Oracle One-to-One Fulfillment component of Oracle E-Business Suite enables a low-privileged attacker with HTTP network access to perform unauthorized creation, deletion, or modification of critical data, and to read any data exposed by the component. The flaw permits confidentiality and integrity compromise without affecting availability. Attacks could result in unauthorized full access to all data handled by the fulfillment service.
Affected Systems
The affected product is Oracle One-to-One Fulfillment (Oracle E-Business Suite) with supported versions 12.2.3 through 12.2.15. No other versions were indicated in the vendor advisory. The CPE matches the product and affected version range.
Risk and Exploitability
With a CVSS v3.1 base score of 8.1, the vulnerability is high severity. EPSS is less than 1%, indicating a low yet nonzero chance of exploitation. The alert is not listed in the CISA KEV catalog. The attack vector is remote, via standard HTTP traffic, requiring no user interface interaction. Successful exploitation relies on insufficient authorization controls, as reflected by associated CWE identifiers.
OpenCVE Enrichment