Impact
The vulnerability allows an attacker with low privilege and network access to the Oracle Common Applications Calendar component via HTTP to create, delete, and modify critical data entries. Successful exploitation can also enable unauthorized access to all data stored in the calendar and trigger a partial denial of service, disrupting legitimate use of the application.
Affected Systems
Oracle Common Applications Calendar for Oracle E-Business Suite, versions 12.2.3 through 12.2.15, are affected. These versions are identified by the vendor as needing remediation.
Risk and Exploitability
The CVSS v3.1 base score of 7.1 denotes moderate severity with high confidentiality and integrity impacts and a lower availability impact. A very low EPSS score of <1% indicates that exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote over HTTP, requiring only low privilege for exploitation, but it is described as difficult to exploit in practice.
OpenCVE Enrichment