Impact
The Human Workflow component of Oracle Business Process Management Suite contains a flaw that can be triggered by an attacker with network access to the T3 or IIOP protocols. The vulnerability enables the attacker to execute code within the context of the application, leading to full compromise of the Business Process Management Suite. The flaw is rated CVSS 3.1 score 9.9, indicating severe confidentiality, integrity, and availability impact.
Affected Systems
Oracle Business Process Management Suite versions 12.2.1.4.0 and 14.1.2.0.0 are affected. This part of Oracle Fusion Middleware can be reached over T3 or IIOP. The functionality is exposed to any user with low privileges on the network.
Risk and Exploitability
The CVSS base score of 9.9 combined with an EPSS score of less than 1% shows a highly critical flaw that is unlikely to be widely exploited yet remains a significant risk. The vulnerability is listed as "not in KEV" but the scope change suggests potential impact on additional Oracle products. Successful exploitation requires only network connectivity to the vulnerable ports; no special credentials are needed. An attacker from an untrusted network can therefore compromise the system by sending the crafted payload over T3 or IIOP.
OpenCVE Enrichment