Impact
A low-privileged attacker with network access via HTTP can exploit a flaw in Oracle Purchasing to create, delete, or modify critical data, and gain full read or write access to all Oracle Purchasing data. The vulnerability delivers high confidentiality and integrity impact as reflected in the CVSS 3.1 Base Score of 8.1.
Affected Systems
The Oracle Purchasing component of Oracle E‑Business Suite is affected, specifically versions 12.2.3 through 12.2.15.
Risk and Exploitability
The flaw can be exploited easily: an attacker only needs network access and a low-privilege account, with no user interaction required. The EPSS score of < 1% indicates a very low chance of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The CVSS vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N confirms that the attack is carried out over the network and damages confidentiality and integrity.
OpenCVE Enrichment