Impact
The vulnerability exists in the Proxy User Delegation component of Oracle User Management. An attacker with only low privileges but who can reach the application over HTTP can exploit the flaw to gain full control of the User Management system. Successful exploitation enables the attacker to read, modify, or delete user data and disrupt availability, thereby breaching confidentiality, integrity, and availability.
Affected Systems
Oracle Corporation’s Oracle User Management product of Oracle E‑Business Suite is affected. The flaw is present in all versions from 12.2.3 through 12.2.15 inclusive.
Risk and Exploitability
The CVSS Base score of 8.8 indicates high severity. The EPSS score of less than 1% suggests that widespread exploitation is unlikely at present, and the issue is not listed in CISA’s KEV catalog. The attack requires only network access over HTTP from a low privileged account, which makes the vulnerability readily exploitable in environments where Oracle User Management is exposed to untrusted networks. The CVSS vector confirms that the exploitation requires network access, low privilege, and no user interaction.
OpenCVE Enrichment