Impact
The vulnerability in Oracle Bills of Material enables an attacker to compromise the component, allowing unauthorized access to critical data and the ability to cause a partial denial of service. The flaw permits bypassing of normal privilege restrictions, granting broader access within the application.
Affected Systems
Affected systems include Oracle Corporation’s Oracle Bills of Material component of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15. Because the vulnerability has a scope change, other related Oracle products may also be impacted if they interact with Bills of Material.
Risk and Exploitability
The CVSS 3.1 base score of 8.5 indicates a high severity, EPSS of 0.00302 means exploitation is currently extremely unlikely. The flaw is not listed in the CISA KEV catalog, yet the potential to expose confidential data and disrupt availability warrants attention. Likely attack vectors involve HTTP traffic to the Bills of Material web interface from unauthenticated or minimally privileged users.
OpenCVE Enrichment