Impact
The Oracle Depot Repair product of Oracle E‑Business Suite (Depot Repair Diagnostics module) contains a vulnerability that can be exploited by an attacker who already has high privileges on the network and can reach the service over HTTP. The flaw permits the creation, deletion or modification of critical data, or provides unauthorized access to all data stored in the Depot Repair component. This results in loss of confidentiality and integrity for all data that the component accesses.
Affected Systems
Oracle Corporation’s Oracle Depot Repair component, part of Oracle E‑Business Suite. Affected versions are 12.2.3 through 12.2.15. Systems running any of these releases should verify whether the vulnerability is present.
Risk and Exploitability
The CVSS 3.1 Base Score of 6.5 reflects a moderate severity with high confidentiality and integrity impact. The EPSS score of less than 1% indicates a low probability of exploitation at present, and it is not catalogued in the CISA KEV list. Exploitation requires an attacker to have high privileges on the network and able to access the service via HTTP; the attack complexity is low, so a knowledgeable adversary could carry out the attack without advanced skills.
OpenCVE Enrichment