Impact
A vulnerability exists in the CRM User Management Framework of Oracle Common Applications that allows a low‑privileged attacker with network access via HTTP to compromise the application. The flaw requires the attacker to obtain user interaction from a person other than the attacker, but once triggered it can lead to unauthorized creation, deletion, or modification of data and unauthorized access to all data that the application can reach. The weakness is an improper authorization flaw that permits elevated permissions without proper validation, resulting in confidentiality and integrity breaches.
Affected Systems
Oracle Common Applications, part of Oracle E‑Business Suite, is affected by the flaw in versions 12.2.3 through 12.2.15. The vulnerability is present in the CRM User Management Framework component of this product, delivered by Oracle Corporation.
Risk and Exploitability
The CVSS v3.1 score of 7.3 indicates a high‑severeness impact. The EPSS score is below 1%, suggesting a very low probability of exploitation at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires HTTP access and a low‑privileged attacker who can obtain user interaction, which limits the attack surface yet still poses a significant threat to confidentiality and integrity for systems that expose the application over the network.
OpenCVE Enrichment