Impact
The vulnerability allows a low‑privileged attacker with HTTP access to create, delete, or modify critical data in Oracle Product Hub, leading to unauthorized data tampering and loss of confidentiality and integrity.
Affected Systems
Oracle Product Hub, a component of Oracle E‑Business Suite, is affected for all supported releases from version 12.2.3 up to 12.2.15 inclusive.
Risk and Exploitability
With a CVSS v3.1 base score of 8.1 and an EPSS probability under 1 %, the issue presents a high impact to confidentiality and integrity but low likelihood of exploitation; attackers need only network reachability to the HTTP endpoint and low privileges to successfully compromise the system, so organizations should treat it as a high‑risk vulnerability.
OpenCVE Enrichment