Impact
A low‑privilege attacker with network access to the HTTP interface can exploit a vulnerability in Oracle Enterprise Command Center Framework, allowing the attacker to read confidential data and modify, insert, or delete records that the framework manages. The vulnerability leads to confidentiality and integrity impacts, but does not provide arbitrary code execution.
Affected Systems
Oracle Corporation’s Oracle Enterprise Command Center Framework, specifically the v16 release. No other product or version information is provided.
Risk and Exploitability
The CVSS 3.1 Base Score is 7.1 and the EPSS score is below 1%, indicating that, while exploitation probability may be low, the attack is considered easily exploitable. The vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is an HTTP session from a low‑privileged network user, as stated in the description.
OpenCVE Enrichment