Impact
This vulnerability in Oracle Product Hub’s internal operations allows an attacker with low privileges to perform unauthorized creation, deletion, or modification of critical data. The weakness is a failure of access controls that permits the attacker to alter information and potentially bypass safeguards intended to protect sensitive data, resulting in significant confidentiality and integrity impact. The CVSS 3.1 base score of 8.1 reflects these risks.
Affected Systems
Oracle Product Hub, a component of Oracle E-Business Suite, is affected for all supported releases from 12.2.3 through 12.2.15. The flaw requires network access via HTTP and can be used by an attacker who does not possess elevated privileges to manipulate data that the product manages.
Risk and Exploitability
The exploit is considered easily exploitable, with a low effort attack vector over HTTP from a low-privilege user. The EPSS score of under 1% indicates a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the high CVSS score warrants immediate attention, as successful exploitation would grant the attacker permanent unauthorized control over the data presented by the Product Hub.
OpenCVE Enrichment