Impact
Vulnerability in the Oracle Common Applications Calendar component of Oracle E‑Business Suite permits a low‑privileged attacker with network access through HTTP to create, delete, or modify critical data and optionally cause a partial denial of service. Exploitation results in unauthorized data tampering and availability impact, as described by the CVSS vector. The flaw stems from insufficient access control that allows users without proper credentials to perform prohibited operations.
Affected Systems
Oracle Common Applications Calendar of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, is affected.
Risk and Exploitability
The CVSS base score of 7.1 indicates moderate to high risk, but the EPSS score of less than 1% suggests exploitation is unlikely at present. The vulnerability is not listed in CISA's KEV catalog. Based on the description, the likely attack vector is HTTP over the network from a low‑privileged account, though final confirmation requires further information.
OpenCVE Enrichment