Impact
The vulnerability allows a low‑privileged attacker with network access over HTTP to perform unauthorized creation, deletion or modification operations, and to read or obtain all data accessible to Oracle Purchasing. This results in a loss of confidentiality and integrity of critical purchasing information.
Affected Systems
Oracle Purchasing, a component of Oracle E‑Business Suite (G‑Invoicing), is affected. Versions 12.2.10 through 12.2.15 support the vulnerability. The issue originates from Oracle Corporation.
Risk and Exploitability
With a CVSS 3.1 base score of 8.1, the flaw is considered high severity. The exploit is network‑based, requiring only low privileges and no user interaction, making it readily exploitable. The EPSS score of < 1% indicates a very low but non‑zero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog, but the high score and ease of exploitation signal a significant risk to affected installations.
OpenCVE Enrichment