Impact
The vulnerability allows a low‑privileged attacker who can reach Oracle Bills of Material over HTTP to create, delete or modify critical data. Successful exploitation results in unauthorized access to or manipulation of all Oracle Bills of Material data, compromising confidentiality and integrity. The weakness arises from inadequate access control in the Internal Operations component, permitting privilege‑level actions beyond those granted to the attacker.
Affected Systems
Oracle Bills of Material component of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15. An attacker with network access to the HTTP interface can exploit the issue.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates a high‑severity impact. The EPSS score of less than 1% suggests that widespread is not listed in the CISA KEV catalog. The low exploitation probability, combined with the requirement for network access and the lack of special privileges, means the vulnerability is most relevant to internal threat actors or attackers who have compromised the network perimeter.
OpenCVE Enrichment