Impact
The vulnerability resides in the Oracle Diagnostics Interfaces component of Oracle Applications Manager. It allows an unauthenticated attacker with network connectivity to HTTP to modify, insert, or delete data and also read a subset of data. The weaknesses result in low confidentiality and low integrity impacts as noted in the CVSS vector and correspond to improper authentication (CWE-306). The likely attack vector is a direct HTTP request to the unprotected Diagnostics Interfaces, and no privileged vehicle is required.
Affected Systems
The affected product is Oracle Applications Manager from Oracle Corporation, with versions ranging from 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS 3.1 base score is 6.5, and the EPSS score is below 1%, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a direct HTTP request to the unprotected Diagnostics Interfaces, and no privileged vehicle is required. Although the current exploitation likelihood is low, the impact on data confidentiality and integrity warrants cautious assessment and timely remediation.
OpenCVE Enrichment