Impact
A vulnerability in Oracle Product Hub, part of Oracle E‑Business Suite, allows an attacker who already possesses high‑privileged access to compromise the product. When exploited, the flaw results in a complete system takeover, compromising confidentiality, integrity, and availability as reflected by a CVSS v3.1 base score of 7.2.
Affected Systems
Oracle Product Hub within Oracle E‑Business Suite, specifically the Internal Operations component. Versions affected are 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS score indicates a moderate‑to‑high severity, while an EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation would occur over the network via the HTTP interface, requires no user interaction, and demands high‑privilege accounts, indicating that a successful attacker could control the Product Hub fully.
OpenCVE Enrichment