Impact
This vulnerability exists in the Client System Analyzer component of Oracle Applications Technology Stack. A remote attacker who can access the system over HTTP can exploit a flaw that does not require any credentials. Upon successful exploitation the attacker can take full control of the stack, gaining confidentiality, integrity, and availability impacts across the affected environment.
Affected Systems
The impact applies to Oracle Corporate products, specifically the Oracle Applications Technology Stack component known as Client System Analyzer. Versions 12.2.3 through 12.2.15 are vulnerable. No other product or version is listed as affected.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 reflects is network based (HTTP) and does not necessitate user interaction, implying that a remote attacker could execute this with minimal effort. Exploit probability is indicated by the EPSS score of less than 1%, suggesting that while the vulnerability is high risk, it is unlikely to be widely seen in the wild at present. The vulnerability is not recorded in the CISA KEV catalog, which aligns with the low EPSS score. Attackers would likely require knowledge of the specific HTTP endpoint that hosts the Client System Analyzer component, but the absence.
OpenCVE Enrichment