Impact
The Oracle Applications Framework component of Oracle E‑Business Suite has a flaw that allows a low‑privileged attacker with network access over HTTP to bypass normal controls, gaining unauthorized read access to critical data that is normally protected. This flaw enables attackers to view or change information within the application, potentially exposing sensitive business data or corrupting records. The weakness falls under improper access control and authorisation failures, impacting both confidentiality and integrity of the application data.
Affected Systems
Oracle Corporation’s Applications Framework is affected. Versions 12.2.9 through 12.2.15 are listed as vulnerable. Systems running these releases that expose the framework’s HTTP interface are susceptible to exploitation.
Risk and Exploitability
The CVSS v3.1 base score of 7.1 indicates moderate to high severity with high confidentiality impact and low integrity impact. The EPSS score of less than 1 % suggests a very low current exploitation probability. The flaw is not yet listed in the CISA KEV catalog, which indicates no known large‑scale exploitation. This flaw is a violation of improper access control (CWE‑284). The most probable attack vector is over the network using HTTP, as the description states the attacker only needs HTTP access and low privileges. Due to the lack of details on the exact trigger mechanism, the exploitability is inferred rather than explicitly documented.
OpenCVE Enrichment