Impact
A vulnerability exists in the Create Item Instance component of Oracle Installed Base within Oracle E-Business Suite. An attacker with low privileges and network access via HTTP can exploit this flaw to create, delete, or modify data that normally requires higher authority. The impact is the unauthorized alteration or deletion of critical data, and the potential to gain unauthorized read access to all data served by Oracle Installed Base. The weakness is a failure of proper access control and privilege management.
Affected Systems
Systems running Oracle Installed Base from versions 12.2.3 through 12.2.15 are affected. These include all installations of the Oracle E-Business Suite that contain the vulnerable Create Item Instance module.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates a high severity with substantial confidentiality and integrity impacts. The EPSS score of less than 1% suggests that, while the vulnerability is exploitable, the probability of it being used in the wild is currently low. The vulnerability is not listed in CISA's KEV catalog. An attacker can reach the vulnerable component over HTTP from the network, requiring only low privileges. If successfully exploited, the attacker can execute unauthorized data operations on the Oracle Installed Base.
OpenCVE Enrichment