Impact
A vulnerability exists in Oracle Product Hub that allows a low‑privileged attacker with network access through HTTP to obtain unauthorized access to critical data and to perform update, insert, or delete operations on data within the Hub. The flaw provides a high confidentiality impact and a lower integrity impact, as reflected in a CVSS 3.1 Base Score of 7.1.
Affected Systems
Oracle Product Hub, part of Oracle E‑Business Suite, is affected. Versions 12.2.3 through 12.2.15 are listed as vulnerable.
Risk and Exploitability
The EPSS score is listed as less than 1%, indicating a very low probability of exploitation. The product is not included in the CISA KEV catalog. However, the CVSS score of 7.1 represents moderate to high severity. The vulnerability can be triggered remotely via HTTP by a low‑privileged attacker, implying that an active network presence on the target environment can lead to a compromise of the Oracle Product Hub’s data security.
OpenCVE Enrichment