Impact
The vulnerability in Oracle Demand Signal Repository allows a low‑privileged attacker who can reach the system over HTTP to create, delete, or modify critical data and to gain unauthorized read or full access to all repository data. The flaw enables both confidentiality and integrity compromise, which means attackers can read sensitive information, corrupt data, or remove critical records. The weakness stems from improper authorization checks. As listed, the CVSS v3.1 base score is 8.1, indicating a high impact when the attack succeeds.
Affected Systems
Affected products are Oracle Demand Signal Repository for Oracle E‑Business Suite, versions 12.2.3 through 12.2.15. The affected component is Internal Operations. The issue applies to every installation that has not applied the latest release or patch.
Risk and Exploitability
The CVSS score of 8.1 reflects strong confidentiality and integrity damage but no availability impact. The EPSS score is below 1 %, suggesting that exploitation is low‑probability, yet the vulnerability is still capable of being exploited over the network without user interaction. The flaw is not listed in CISA’s KEV catalog, but the high score and direct HTTP access mean that an attacker could reach the target from any connected network segment. The attack path requires only network connectivity to the HTTP service and does not require privileged credentials.
OpenCVE Enrichment