Impact
A low‑privileged attacker with network access over HTTP can exploit an easily exploitable flaw in Oracle Contract Lifecycle Management for Public Sector to compromise the application. The vulnerability can lead to a full takeover of the system, giving the attacker full confidentiality, integrity, and availability control. The CVSS 3.1 base score of 8.8 reflects severe impacts in all three dimensions.
Affected Systems
Oracle Corporation’s Contract Lifecycle Management for Public Sector, version 16, is affected. The vulnerability is present in the ECC For Award and IDV component of the Oracle E‑Business Suite.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, and the EPSS score of less than 1 % suggests that exploitation is unlikely at present, but the risk is amplified by the absence of a KEV listing. The attack vector is network‑based via HTTP, and because the privilege requirement is low, an attacker who can reach the application can manipulate it without a need for privileged credentials. Successful exploitation can occur without authentication or with minimal privileges, allowing complete takeover of the application. The lack of a KEV listing means no widely distributed exploit is publicly known, but the high CVSS, coupled with network exposure, warrants proactive mitigation.
OpenCVE Enrichment