Impact
The vulnerability in the Oracle Bills of Material product within Oracle E‑Business Suite allows a low‑privileged attacker with network access via HTTP to fully compromise the application. Successful exploitation can result in a complete takeover of Oracle Bills of Material, granting the attacker full confidentiality, integrity, and availability impact.
Affected Systems
Affected systems are the Oracle Bills of Material component within Oracle E‑Business Suite, specifically the Setup Workbench product. Versions that are impacted range from 12.2.3 through 12.2.15, as listed by the vendor's advisory.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates high severity, and the EPSS score of < 1% suggests the likelihood of exploitation is currently low, though the vulnerability is not listed in CISA's KEV catalog. The attack vector is remote over HTTP, requiring only network connectivity and low privilege, making it an attractive target for adversaries on the same network or with port access, and an unpatched instance exposes the full application layer for takeover.
OpenCVE Enrichment