Impact
A vulnerability in Oracle Purchasing allows an attacker who can access the system over HTTP and who has low‑privileged credentials to compromise the application. The flaw enables an attacker to gain full control of the system, resulting in loss of confidentiality, integrity, and availability. The weakness is characterized by improper access control, as indicated by the listed CWEs.
Affected Systems
Oracle Purchasing versions 12.2.3 through 12.2.15 are vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 classifies the vulnerability as high risk. The EPSS score is below 1%, suggesting a low probability of exploitation in the short term, but the flaw remains exploitable for anyone with network access to the HTTP interface and low‑privileged accounts. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by sending malicious requests over the network, taking advantage of the weak access control to take full control of the application.
OpenCVE Enrichment