Impact
A low‑privileged attacker with network access over HTTP can exploit a flaw in Oracle Depot Repair’s Recall Management component. The vulnerability allows the attacker to read sensitive data or gain full access to all data exposed by Oracle Depot Repair and, if desired, induce a partial denial of service. The vulnerability maps to CWE-400. The impact is high on confidentiality and low on availability, as indicated by the CVSS vector.
Affected Systems
The affected product is Oracle Depot Repair for Oracle E‑Business Suite, specifically versions 12.2.3 through 12.2.15. This applies only to the Recall Management module within the depot repair component of the suite.
Risk and Exploitability
The CVSS score of 7.1 reflects a medium‑to‑high severity, with a low exploitation probability (EPSS < 1%) and no listing in the CISA KEV catalog. The attack vector is network based and requires only low privilege access, implying that anyone with network connectivity to the application could potentially exploit this without local system access. Because the vulnerability allows unauthorized data access and partial service disruption, organizations with exposed Depot Repair in the network should treat this as an immediate patching priority.
OpenCVE Enrichment