Impact
A flaw in Oracle Complex Maintenance, Repair and Overhaul allows an attacker with low privileges to reach the system over HTTP, read confidential information, obtain full access to all exposed data, and trigger a partial denial of service. The weakness results in a high confidentiality impact and a low availability impact as documented by the CVSS Base Score of 8.5.
Affected Systems
The vulnerability applies to Oracle E‑Business Suite instances of the Complex Maintenance, Repair and Overhaul component, specifically supported releases 12.2.12 through 12.2.15. The affected portion is the Internal Operations module, with the potential to extend across other Oracle products due to the scope change flag in the CVSS vector.
Risk and Exploitability
EPSS indicates a below‑1 % probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, yet the high CVSS score signals a serious risk. Attackers can launch the exploit remotely from any network host capable of reaching the service, requiring only low privileges to initiate the breach. If successful, the attacker can compromise data confidentiality completely and disrupt service availability to a partial degree, impacting business operations.
OpenCVE Enrichment