Impact
Vulnerability in Oracle E-Business Suite’s Oracle Order Management product, specifically in the Product Diagnostic Tools component, allows an attacker with low privileges and network access via HTTP to bypass authorization controls and manipulate critical data. The flaw can be exploited to create, delete or modify data and to read any data accessible within the application, causing serious confidentiality and integrity breaches. The weakness is a classic improper authorization issue.
Affected Systems
Oracle Order Management 12.2.4 through 12.2.15 are affected by this vulnerability.
Risk and Exploitability
The CVSS v3.1 score of 8.1 indicates high severity, with high confidentiality and integrity impacts. The EPSS score of less than 1% suggests a low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can target the exposed HTTP endpoints from anywhere on the network, and because the flaw permits low-privileged users to override access checks, an exploiter can gain unauthorized data access and manipulation with relative ease.
OpenCVE Enrichment