Impact
This vulnerability permits a low‑privileged attacker who can reach the Oracle Engineering component over HTTP to create, delete, or modify critical data without proper authorization. The flaw results in unauthorized access to all data managed by Oracle Engineering, causing both confidentiality and integrity violations. The CVSS 3.1 base score of 8.2 underlines the severity with a high impact on confidentiality and integrity while the availability is not affected.
Affected Systems
Oracle Engineering, part of Oracle E‑Business Suite, is affected for supported releases from 12.2.3 through 12.2.15. The issue resides in the Internal Operations module. Attackers may also impact other components of Oracle E‑Business Suite due to a scope change. System administrators should verify that the version in use falls within this range.
Risk and Exploitability
The vulnerability can be exploited over the network using HTTP (AV:N) with high attack complexity (AC:H) and low privileges (PR:L) and no user interaction (UI:N). The EPSS score of less than 1% indicates a very low probability of widespread exploitation at this time, and it is not listed in the CISA KEV catalog. Nevertheless, the high CVSS score (8.2) and the potential for scope escalation warrant immediate attention from security teams.
OpenCVE Enrichment