Impact
A vulnerability exists in Oracle Purchasing’s G‑Invoicing component that allows an attacker with limited local privileges and network access via HTTP to create, delete, or modify critical data. Successful exploitation leads to unauthorized manipulation of all accessible Oracle Purchasing data, impacting confidentiality and integrity as reflected by the CVSS score of 8.1. The weakness is a form of improper access control, allowing attackers to bypass defined data protection mechanisms.
Affected Systems
Oracle Corporation’s Oracle Purchasing product for E‑Business Suite, specifically versions 12.2.11 through 12.2.15, is susceptible to this flaw.
Risk and Exploitability
The CVSS indicates significant risk with high confidentiality and integrity impact, while the EPSS score of fewer than 1% suggests low exploitation probability at this time. The vulnerability is not catalogued in CISA’s KEV. The likely attack vector involves remote network activity over HTTP, requiring only low privileges to compromise Oracle Purchasing. An attacker could leverage this to gain full access to or alter corporate data within the application without affecting availability.
OpenCVE Enrichment