Impact
The vulnerability resides within the Self‑serv What‑if Analysis component of Oracle Advanced Benefits and enables a high‑privileged attacker with network access over HTTP to compromise the application. Successful exploitation results in full control of Oracle Advanced Benefits, affecting confidentiality, integrity, and availability of the data and services it manages. The attack requires a network connection to the application and benefits from a lack of proper access control.
Affected Systems
Oracle Corporation’s Oracle Advanced Benefits, versions 12.2.3 through 12.2.15, are impacted. The vulnerability is specific to the Self‑serv What‑if Analysis component but can have broader implications for other products in the Oracle E‑Business Suite ecosystem.
Risk and Exploitability
The CVSS v3.1 Base Score of 8.0 reflects high severity, with the attack requiring network access, high privileges, and no user interaction. The EPSS score of less than 1% indicates a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because the vulnerability allows a high‑privileged attacker to take over Oracle Advanced Benefits, it represents a significant threat, especially if the attacker already has network access. The likely attack path involves sending a specially crafted HTTP request to the Self‑serv What‑if Analysis endpoint, exploiting insufficient authorization checks to gain elevated privileges.
OpenCVE Enrichment