Impact
This vulnerability allows an attacker with low privileges and network access via HTTP to fully compromise the Oracle Product Hub. The flaw permits the attacker to bypass authentication boundaries, resulting in complete loss of confidentiality, integrity, and availability of the product hub. The CVSS v3.1 base score is AV:N, AC:L, PR:L, UI:N, S:U, C:H, I:H, A:H. Oracle Product Hub is part of Oracle E‑Business Suite.
Affected Systems
Oracle Corporation's Oracle Product Hub, versions 12.2.3 through 12.2.15.
Risk and Exploitability
The vulnerability carries a high CVSS 8.8 score and is network host that can reach the HTTP endpoint of the product hub. EPSS score is reported as <1%, indicating a very low exploitation probability, and the flaw is not listed in CISA KEV. An attacker who succeeds can take over the product hub, compromising its confidentiality, integrity, and availability for the hosting environment.
OpenCVE Enrichment