Impact
The Oracle Product Hub component of Oracle E‑Business Suite contains an easily exploitable flaw that allows an attacker with high privileges and basic network access over HTTP to compromise the product. Successful exploitation can result in full takeover of Oracle Product Hub, with impacts on confidentiality, integrity, and availability for all data and services managed through the hub. The issue is classified with a CVSS 3.1 base score of 7.2, reflecting significant damage potential when the attacker can authenticate and gain elevated access.
Affected Systems
The affected product is Oracle Product Hub within the Oracle E‑Business Suite environment, specifically the Internal Operations component. The known vulnerable range is versions 12.2.3 through 12.2.15. Any deployment of those versions remains susceptible until the official fix is applied or the product is upgraded beyond the affected release.
Risk and Exploitability
The CVSS score of 7.2 places the vulnerability in the high‑severity range, while the EPSS score of less than 1 % indicates a very low probability of exploitation in the wild at present. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed public exploits yet. Nonetheless, the attack vector is network based over HTTP, and the user or process with network connectivity could potentially reach and exploit the flaw. Organizations should treat this as a significant concern for environments where Oracle Product Hub is exposed to untrusted networks or where privileged users may be compromised.
OpenCVE Enrichment