Impact
A vulnerability in Oracle Complex Maintenance, Repair and Overhaul permits a low‑privileged attacker with network access through HTTP to compromise the system. Successful exploitation results in full takeover, leading to confidentiality, integrity, and availability losses. Based on the description, it can be inferred that the flaw may involve improper access control or authentication mechanisms, but the specific weakness type is not explicitly stated.
Affected Systems
The affected product is Oracle Complex Maintenance, Repair and Overhaul, part of Oracle E‑Business Suite Internal Operations. Versions 12.2.3 through 12.2.15 are impacted. Users running these releases should verify their environment and consult Oracle for supported fixes.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates a high impact vulnerability, while the EPSS below 1 % and the absence from the CISA KEV catalog suggest low exploitation probability. Based on the description, the likely attack path involves an unauthenticated or low‑privileged HTTP session that may bypass access controls to execute arbitrary commands, but the exact vulnerability mechanism is not documented.
OpenCVE Enrichment