Impact
The Oracle Product Hub component of Oracle E‑Business Suite contains an easily exploitable flaw that permits a low‑privileged attacker with network access to HTTP endpoints to compromise the application. Successful exploitation can lead to full takeover of Oracle Product Hub, resulting in total loss of confidentiality, integrity, and availability of the system. The vulnerability is reflected in a CVSS v3.1 base score of 8.8, indicating high severity across all three core security categories.
Affected Systems
Affected installations are Oracle Product Hub releases 12.2.3 through 12.2.15, all currently supported. These versions include the Internal Operations component that is susceptible to the flaw. The vulnerability applies to all variants of the product within this version window.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability poses a serious threat. The EPSS score is lower than 1 %, suggesting that, by and large, exploits are not yet widely deployed, and the issue is not listed in CISA’s KEV catalog. The attack vector is straightforward—an adversary only needs network connectivity to an HTTP service, and no privileged credentials are required. The combination of a low attack effort and complete compromise makes the risk significant for exposed systems.
OpenCVE Enrichment