Impact
A flaw exists in Oracle Order Management, allowing an attacker with low privileges who can reach the system over HTTP to obtain unauthorized access to critical data or all Order Management information. Successful exploitation can lead to reading confidential information and modifying, inserting, or deleting data, which results in high confidentiality loss and some integrity compromise. The weakness manifests as improper access control allowing unauthorized manipulation of data.
Affected Systems
The affected product is Oracle Order Management, part of Oracle E-Business Suite, specifically version v16. Organizations using this version are directly impacted.
Risk and Exploitability
The CVSS v3.1 score of 7.1 indicates a moderate to high severity, with potential for significant confidentiality impact. The EPSS score is below 1%, suggesting a low current probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is the network over HTTP, targeting users with low level access privileges. Successful exploitation requires no user interaction, and the impact is confined to the scope of the compromised application.
OpenCVE Enrichment