Impact
The Oracle Enterprise Command Center Framework version 16 contains a flaw that permits an unauthenticated attacker who can reach the physical communication segment attached to the hardware to take control of the framework. This vulnerability is a CWE‑284 Access Control weakness that, once exploited, results in a takeover of the framework, defeating confidentiality, integrity, and availability of the entire system.
Affected Systems
Oracle Enterprise Command Center Framework, part of Oracle E‑Business Suite, version 16. The affected component is the core framework of the product, under the Oracle brand. No other vendors or product versions are documented as affected.
Risk and Exploitability
The likely attack vector requires access to the physical communication segment of the hardware; this is an inferred local network path based on the description. The vulnerability carries a CVSS 3.1 base score of 7.5, indicating moderate to high severity with full confidentiality, integrity, and availability impacts. The EPSS score is less than 1%, suggesting a low current exploitation probability, and the issue is not listed in the CISA KEV catalog. Although exploitation conditions are restrictive, the potential for a complete compromise warrants attention for systems exposed to such access.
OpenCVE Enrichment