Impact
The vulnerability in Oracle Outside In Technology’s Outside In Core component allows an unauthenticated attacker who has logged onto the infrastructure where the software runs to compromise the application. It requires the attacker to have local access and no privileges, and it also requires human interaction from a person other than the attacker. Successful exploitation can lead to complete takeover, resulting in confidentiality, integrity, and availability loss. The CVSS 3.1 base score is 7.8, reflecting high impact with the vector (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Affected Systems
The affected product is Oracle Outside In Technology (Outside In Core) version 8.5.8, which is part of Oracle Fusion Middleware. No other versions or products are listed as affected.
Risk and Exploitability
The high confidentiality, integrity, and availability impacts, coupled with a local attack vector requiring no privileges, underscore the risk of this vulnerability. The EPSS score of <1% indicates a low probability of exploitation at any given time; however, the CVSS base score of 7.8 and the potential for complete takeover underscore the need for immediate remediation, preferably through an official vendor patch if available.
OpenCVE Enrichment