Impact
The vulnerability is an access‑control flaw in Oracle Enterprise Command Center Framework version 16 that allows a high‑privileged attacker who can reach the HTTP interface to compromise the entire framework. It is classified as CWE‑284 and gives an attacker full control, enabling the reader, modification, or deletion of any data or configuration within the framework, as well as the ability to disrupt its availability.
Affected Systems
Oracle Enterprise Command Center Framework from Oracle Corporation, version V16, is listed as the only vulnerable release.
Risk and Exploitability
The CVSS 3.1 base score of 7.2 indicates high severity, while the EPSS score of less than 1 % suggests that widespread exploitation is unlikely at present. The vulnerability is not listed in CISA KEV. The likely attack vector is network access to the HTTP interface, requiring an attacker to have high privileges within the system to successfully exploit the flaw and gain full control of the framework.
OpenCVE Enrichment