Impact
A vulnerability in Oracle’s Depot Repair component of Oracle E‑Business Suite enables an attacker who has high privileged credentials and network access over HTTP to compromise the application. The vulnerability affects Oracle E‑Business Suite versions 12.2.3 through 12.2.15. Successful exploitation can result in a full takeover of the Depot Repair service, causing loss of confidentiality, integrity, and availability for the affected business processes. The weakness is defined by the CVSS vector AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H, which indicates that the vulnerability is remotely exploitable with manual effort and requires high privilege to gain control.
Affected Systems
Oracle Depot Repair within Oracle E‑Business Suite is affected, specifically the internal operations component. All supported release versions from 12.2.3 through 12.2.15 contain the flaw.
Risk and Exploitability
The CVSS score of 7.2 marks the issue as high severity, yet the EPSS score of less than 1% suggests a very low chance of exploitation in practice. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to access the service over HTTP and possess high‑privilege credentials to succeed in a takeover.
OpenCVE Enrichment