Impact
The vulnerability in Oracle Application Object Library (CWE‑284) permits an unauthenticated attacker with network access over HTTP to gain authority to create, delete, or modify critical data or to gain full access to all data exposed by the library. This leads to high impacts to confidentiality and integrity, as documented by a CVSS score of 7.4.
Affected Systems
Affected versions are Oracle E‑Business Suite Oracle Application Object Library 12.2.3 through 12.2.15, released by Oracle Corporation.
Risk and Exploitability
The weakness is exploitable from any networked host that can reach the HTTP endpoint, requiring high effort but no authentication. The EPSS score is less than 1 %, indicating a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Despite the low EPSS, the high CVSS score and the potential for unauthorized data modification warrant careful monitoring and mitigation.
OpenCVE Enrichment