Impact
A vulnerability in the Oracle Bills of Material Setup Workbench component allows a network attacker with high-level privileges accessing the application over HTTP to fully take control of the application, resulting in loss of confidentiality, integrity, and availability for the affected instance. The flaw involves improper privilege management and privilege escalation. While the vulnerability is confined to Oracle Bills of Material, attacks may also impact other components of the Oracle E-Business Suite due to the scope change.
Affected Systems
Oracle Bills of Material, versions 12.2.3 through 12.2.15, supplied by Oracle Corporation as part of the Oracle E-Business Suite.
Risk and Exploitability
The CVSS 3.1 base score of 8.0 indicates high severity. The EPSS score of less than 1% signals a low probability of exploitation, and the vulnerability is not listed in CISA KEV. The attack vector is remote over HTTP; a high-privileged attacker with network access can exploit the flaw. Successful exploitation can result in takeover of Oracle Bills of Material and potentially other components of the suite.
OpenCVE Enrichment