Impact
The Oracle Enterprise Command Center Framework (version 16) contains an access‑control flaw that permits an unauthenticated attacker who can reach the physical communication segment attached to the hardware to create, delete, or modify critical data. The vulnerability allows a full breach of confidentiality and integrity for all data accessible by the framework, and it can also affect other Oracle E‑Business Suite modules that rely on the same communication layer, potentially broadening the impact scope.
Affected Systems
Oracle Enterprise Command Center Framework version 16, a component of Oracle E‑Business Suite Core. The description indicates that attacks may also impact other Oracle E‑Business Suite modules that share the same communication layer, although only this framework version is explicitly listed as vulnerable.
Risk and Exploitability
The CVSS base score of 8.0 marks the vulnerability as high severity, while the EPSS score of fewer than 1% suggests an extremely low probability of exploitation at this time. The flaw is not listed in CISA’s KEV catalog. Exploitation requires physical access to the hardware communication interface, a condition that reduces the attack surface but still poses a significant risk to on‑premises deployments where such access is possible. Successful exploitation would grant an attacker unrestricted confidentiality and integrity compromise for all data managed by the framework and any dependent applications.
OpenCVE Enrichment