Impact
The vulnerability resides in the Search Bean component of Oracle Applications Framework within Oracle E‑Business Suite and is classified as an improper access control flaw. It allows an attacker with low‑privileged access over HTTP to compromise the framework, resulting in loss of confidentiality, integrity, and availability for the application.
Affected Systems
Oracle Applications Framework for Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score of less than 1% suggests that exploitation is unlikely in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based via HTTP and requires only low‑privileged access to the application; successful exploitation gives the attacker complete control of the Oracle Applications Framework.
OpenCVE Enrichment