Impact
The vulnerability resides in the Internal Operations component of Oracle Financials for Asia/Pacific (Oracle E‑Business Suite) versions 12.2.8 through 12.2-15 and allows an attacker with network access via HTTP and low privileges to create, delete, or modify critical data and to partially disrupt service. This leads to confidentiality, integrity, and availability breaches as reflected by the CVSS 8.3 score.
Affected Systems
Affected systems include Oracle Financials for Asia/Pacific from Oracle, specifically versions 12.2.8 to 12.2.15 of the Oracle E‑Business Suite applied in Asia/Pacific regions.
Risk and Exploitability
The CVSS score of 8.3 coupled with an EPSS probability of below 1% indicates a high severity yet low likelihood of current exploitation. Based on the description, the likely attack vector is through HTTP requests, and the vulnerability can be leveraged over the network without requiring elevated credentials. This allows a low‑privileged attacker to bypass access controls. Although not yet listed in the CISA KEV catalog, the potential for unauthorized data manipulation requires immediate attention and monitoring.
OpenCVE Enrichment