Impact
A vulnerability in Oracle’s Complex Maintenance, Repair and Overhaul component of Oracle E-Business Suite allows an attacker with low privileges to gain complete control over the application. The flaw can be triggered over HTTP and, if successfully exploited, grants the attacker full takeover of the system, compromising confidentiality, integrity, and availability of the affected environment. This aligns with CWE‑284, identifying improper access control as the underlying weakness.
Affected Systems
The affected product is Oracle Complex Maintenance, Repair and Overhaul, part of Oracle E‑Business Suite. Versions within the range 12.2.3 to 12.2.15 are vulnerable. No specific sub‑versions are identified beyond this range, and the issue is tied to the internal operations component of the application.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability. The EPSS score of less than 1% suggests that real‑world exploitation is unlikely at present, yet the impact remains serious should an exploit be discovered. The vulnerability is not listed in the CISA KEV catalog, but networks with open HTTP access to Oracle Complex Maintenance, Repair and Overhaul should treat this issue with priority, as the attack vector is remote and requires only low privilege.
OpenCVE Enrichment