Impact
The vulnerability allows an attacker with low privileges who can reach the Oracle Sourcing web interface to remotely execute code and take full control of the application. Successful exploitation results in compromise of confidentiality, integrity and availability of the Oracle Sourcing component, effectively giving the attacker full takeover of the affected system. The weakness is classified as an improper access control flaw that permits exploitation over the network without needing elevated privileges.
Affected Systems
Oracle Sourcing (Oracle E‑Business Suite, component Internal Operations) versions 12.2.3 through 12.2.15 are affected. The issue is present in all builds within that range that have not been patched by Oracle’s security advisory.
Risk and Exploitability
The CVSS v3.1 score of 7.5 indicates a high severity vulnerability. The EPSS score is below 1 %, indicating a low probability of being exploited in the wild, but the risk remains significant because the impact is full takeover of the application. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over HTTP traffic to the Oracle Sourcing web interface; a low‑privileged attacker, once able to connect to the internal network or an exposed service, can exploit the flaw without additional credentials.
OpenCVE Enrichment