Impact
A low‑privileged attacker who can reach the Oracle Depot Repair HTTP interface can exploit an improperly enforced access control. The attack allows the attacker to create, delete, or modify critical data in the Estimate and Actual Charges component, and to read all data visible through the interface. This leads to confidentiality and integrity failures, with the attacker gaining full control over the affected business data.
Affected Systems
Oracle Corporation’s Oracle Depot Repair product, part of Oracle E‑Business Suite, is affected. Versions 12.2.3 through 12.2.15 are vulnerable. No later releases are known to contain the fix.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 classifies the flaw as high severity. The EPSS score of less than 1 % indicates that exploitation attempts are currently uncommon, but the vulnerability is not included in CISA’s KEV catalog. The flaw is reachable via the public HTTP interface and requires only low‑privileged credentials, making it attractive to a broad range of threat actors.
OpenCVE Enrichment