Impact
Oracle Purchasing is vulnerable to an access-control failure that permits an attacker with low privileges and network connectivity over HTTP to create, modify, delete, or otherwise alter critical data. The flaw also allows unrestricted access to all data reachable by the application, compromising both confidentiality and integrity of Oracle Purchasing data.
Affected Systems
Oracle Purchasing within Oracle E-Business Suite, supporting versions 12.2.3 through 12.2.15. The issue does not affect other Oracle products and is limited to this specific application component.
Risk and Exploitability
The flaw carries a CVSS 3.1 base score of 8.1, indicating high severity; the EPSS score of <1% suggests limited automated exploitation but still plausible manual attacks. It is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability by sending crafted HTTP requests to a low-privileged account. Based on the description, it is inferred that OS privileges are not required to exploit this vulnerability, and no complex configuration is necessary.
OpenCVE Enrichment