Impact
This vulnerability permits a low‑privileged network attacker who can reach the Oracle Enterprise Command Center Framework over HTTP to bypass authorization controls and perform unauthorized actions. An attacker can create, delete, or modify critical data, read restricted subsets of data, and cause the application to hang or crash, leading to denial of service. The weakness combines an access‑control flaw (CWE‑284), a resource‑exhaustion vulnerability (CWE‑400), and potential SQL injection (CWE‑89). The impact includes low confidentiality loss, high integrity compromise, and high availability disruption, reflected in the CVSS 3.1 score of 8.3.
Affected Systems
The affected product is Oracle Corporation’s Enterprise Command Center Framework, version 16. No other versions or variants are known to be affected, and the issue is specific to this release. The product is part of Oracle E‑Business Suite and the description indicates that version v16 is impacted. There is no evidence suggesting that earlier or later releases are vulnerable.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low probability of widespread exploitation. The attack vector is network‑based HTTP; an attacker only needs network access to the framework on the specified version. Even so, the severity of the potential damage—unauthorized data manipulation, read access, and complete denial of service—makes the overall threat level high, emphasizing the need for prompt remediation.
OpenCVE Enrichment