Impact
The vulnerability in Oracle Engineering, part of Oracle E‑Business Suite's Change Management component, permits a low‑privileged attacker with network access via HTTP to compromise the system. Successful exploitation can lead to unauthorized access to critical data or full access to all data available through Oracle Engineering. The flaw is classified as a confidentiality‑only impact, with no direct integrity or availability effects, and is rated a CVSS 3.1 base score of 7.7.
Affected Systems
Affected across Oracle Corporation’s Oracle Engineering product for Oracle E‑Business Suite, specifically the Change Management component. The vulnerability applies to supported versions 12.2.3 through 12.2.15 inclusive.
Risk and Exploitability
The CVSS score of 7.7 indicates a high level of severity, yet the EPSS score is below 1 % and the vulnerability is not listed in CISA KEV, suggesting limited exploitation activity at present. However, the attack vector is via the public HTTP interface, requiring only low privileges, meaning that if an attacker gains network reach to the service, exploitation is relatively straightforward. Security teams should be wary of the confidentiality risks this presents, especially since the scope change may affect other Oracle products.
OpenCVE Enrichment