Impact
A flaw in Oracle Financials Common Modules permits an attacker with only network access through HTTP to create, delete, or alter data that normally requires higher privileges. The vulnerability is a form of unchecked access control, allowing unauthorized users to compromise the confidentiality and integrity of financial data. This weakness is identified as CWE-284, Unauthorized Access.
Affected Systems
Oracle Corporation’s Oracle Financials Common Modules, versions 12.2.3 through 12.2.15, are affected. The flaw resides in the Common Components of the E-Business Suite and can be exploited in any deployment of those specific versions.
Risk and Exploitability
The base CVSS score of 8.1 denotes a high severity, while the EPSS score of less than 1% suggests that exploitation is presently uncommon. The vulnerability is not listed in the CISA KEV catalog, but it can still be user who can reach the HTTP data manipulation rights, compromising both confidentiality and the low effort and no special conditions, the threat remains significant for exposed systems.
OpenCVE Enrichment