Impact
The vulnerability is an access‑control flaw in Oracle Enterprise Command Center Framework version 16 that allows a high‑privileged attacker who can reach the HTTP interface to compromise the entire framework. It is classified as CWE‑284 and also includes a privilege‑escalation weakness CWE‑269, giving an attacker full control to read, modify, delete data or configuration, and disrupt availability.
Affected Systems
Oracle Enterprise Command Center Framework from Oracle Corporation, version V16, is the only vulnerable release.
Risk and Exploitability
The CVSS 3.1 base score of 7.2 indicates high severity, while the EPSS score of less than 1 % suggests that widespread exploitation is unlikely at present. The vulnerability is not listed in CISA KEV. The likely attack vector is network access to the HTTP interface, requiring an attacker to have high privileges within the system to successfully exploit the flaw and gain full control of the framework.
OpenCVE Enrichment