Impact
The Oracle Contracts product in Oracle E‑Business Suite has a vulnerability that allows a low‑privileged attacker with network access over HTTP to compromise the system. Successful exploitation can lead to complete loss of confidentiality, integrity and availability of the application.
Affected Systems
Affected products are Oracle Contracts within Oracle E‑Business Suite, specifically versions 12.2.14 and 12.2.15. These are the only versions identified as vulnerable.
Risk and Exploitability
The CVSS base score is 8.8, indicating a high severity vulnerability. The EPSS score is less than 1%, suggesting a low probability of exploitation in the wild at this time. The vulnerability is not listed in the CISA KEV catalog. An attacker only requires a low level of privilege and no user interaction to exploit the flaw via HTTP, making the attack vector relatively straightforward for an adversary with network access.
OpenCVE Enrichment