Impact
The vulnerability is an authorization flaw that allows low‑privileged users who can reach the Demand Signal Repository via HTTP to perform any create, delete, or modify operation on the repository data. This capability enables an attacker to access any stored information, directly compromising confidentiality and integrity while keeping the system available.
Affected Systems
Oracle Corporation’s Demand Signal Repository, part of Oracle E‑Business Suite, is affected for supported releases 12.2.3 through 12.2.15. The flaw exists in the Internal Operations component and can be triggered by any network user who can contact the repository’s HTTP port.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 reflects high confidentiality and integrity impact. The EPSS score of less than 1% indicates a very low but nonzero exploitation likelihood at present, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread exploitation yet. The likely attack vector is remote via typical HTTP traffic, requiring only low privileges on the target network, meaning the issue is a high‑risk concern that should be addressed promptly.
OpenCVE Enrichment