Impact
A flaw in Oracle Bills of Material’s Setup Workbench enables a low‑privileged attacker with network access via HTTP to gain unauthorized access to critical data. The vulnerability, rated CVSS 7.7, is easily exploitable and can lead to full access to all database objects exposed by the product. The weakness corresponds to improper access control and improper privilege management, leaving confidentiality severely impacted while integrity and availability remain largely unaffected.
Affected Systems
Oracle Bills of Material, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected. The vulnerability operates in the Setup Workbench component and may also influence other Oracle products that rely on the same data layer.
Risk and Exploitability
The CVSS 7.7 score indicates high severity, but the EPSS score of less than 1% shows that the likelihood of exploitation in the wild is currently low. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit it remotely without authentication but require low‑privilege access, making the attack vector network‑based HTTP. Successful exploitation can lead to confidential data leakage or complete loss of control over Bills of Material data.
OpenCVE Enrichment