Impact
The vulnerability is an access‑control flaw that allows a low‑privileged attacker with network access to the Demand Signal Repository to create, delete, or modify critical data and to cause a hang or repeatable crash, effectively denying service. The problem manifests over HTTP, providing direct remote interaction with the internal operations component, and results in high integrity and availability impact.
Affected Systems
Oracle Demand Signal Repository, part of Oracle E‑Business Suite, is affected in versions 12.2.3 through 12.2.15. Only these releases contain the vulnerable component, which is accessed over HTTP within the internal operations subsystem.
Risk and Exploitability
The CVSS score of 8.1 indicates a serious severity, while the EPSS score of less than 1% suggests the exploit is not widely deployed at present. The vulnerability is not listed in CISA’s KEV catalog. Attackers can reach the vulnerable interface remotely, require only low privileges, and do not need a user interface, making the exploitation path straightforward.
OpenCVE Enrichment