Impact
The vulnerability is an access‑control flaw that permits a high‑privileged attacker to gain unauthorized access to, and modify, data in Oracle Enterprise Command Center Framework over HTTP. Successful exploitation leads to confidentiality and integrity impacts, as the attacker can retrieve critical data or perform unauthorized updates, inserts, or deletes. The CVSS 3.1 base score of 7.6 reflects these impacts and indicates a high severity threat for systems using the affected configuration. While the flaw resides in Oracle Enterprise Command Center Framework, the vulnerability may also affect other Oracle products due to a scope change.
Affected Systems
Oracle Corporation’s Oracle Enterprise Command Center Framework, part of Oracle E-Business Suite, specifically the Core component in version 16 is impacted. In addition, the vulnerability may affect other Oracle products due to a scope change, potentially extending its impact beyond the core component.
Risk and Exploitability
The CVSS score of 7.6, combined with an EPSS score of less than 1%, indicates that while the vulnerability is serious, the probability of exploitation remains low. It is not listed in the CISA KEV catalog. The likely attack vector is network‑based over HTTP, requiring the attacker to have high privileges within the network or compromised credentials. While the flaw resides in Oracle Enterprise Command Center Framework, the vulnerability may also affect additional Oracle products due to a scope change, potentially broadening the impact. No additional exploitation conditions are noted in the advisory, so any user with sufficient privileges on the network can potentially exploit this flaw.
OpenCVE Enrichment