Impact
The flaw in Oracle Bills of Material permits a low‑privilege attacker with network access over HTTP to create, delete, or modify critical data. This is a broken access control weakness that compromises confidentiality and integrity of billing information and can extend to other components of the E‑Business Suite by broadening the scope of the compromise. The vulnerability is classified as CWE‑284 and can cause unauthorized data modification and potential full data exposure.
Affected Systems
Oracle Bills of Material (Oracle E‑Business Suite) versions 12.2.13 through 12.2.15 are affected. These releases expose Bills traffic without proper authorization checks, enabling low‑privileged users to act like administrators.
Risk and Exploitability
The CVSS 3.1 base score of 8.2 reflects high confidentiality and integrity impact. The EPSS score is less than 1%, indicating a low probability of exploitation, and the flaw is not listed in CISA KEV. Based on the description, the likely attack vector is HTTP from a network attacker with low privileges, which, if successful, can alter or delete data and potentially affect other Oracle E‑Business Suite components.
OpenCVE Enrichment