Impact
A low‑privileged attacker with network access via HTTP can exploit this Oracle vulnerability to read critical data and perform unauthorized updates or deletions. The CVSS vector indicates network access, low attack complexity, low privilege requirement, and no user interaction, resulting in a confidentiality impact of high and integrity impact of low. This means the attacker can potentially gain significant information and alter data integrity without the need for direct user involvement.
Affected Systems
Oracle Contract Lifecycle Management for Public Sector, versions 12.2.8 through 12.2.15 are affected. The vulnerability resides in the Award/PO component of this product.
Risk and Exploitability
The CVSS base score of 7.1 classifies the vulnerability as high severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. However, the lack of a KEV listing does not diminish the risk; an attacker who reaches the application can achieve significant data compromise. The likely attack path is over the public HTTP interface with a low‑privilege account, enabling the attacker to bypass authorization controls.
OpenCVE Enrichment