Impact
The flaw exists in the Search Bean component of Oracle Applications Framework, allowing a low‑privileged attacker who can reach the system over HTTP to bypass authorization and obtain full control. This weakness results in confidentiality, integrity, and availability impacts, reflected by a CVSS v3.1 base score of 8.8.
Affected Systems
Oracle Applications Framework versions 12.2.3 through 12.2.15 in Oracle E‑Business Suite are affected. Any installation of these releases without the security update is vulnerable, and no specific build beyond that range is listed.
Risk and Exploitability
The EPSS score is below 1%, indicating a low current likelihood of exploitation, but the high CVSS score and absence of a KEV listing imply that if an attacker discovers the vulnerability it can be leveraged with simple network access to the HTTP interface. Attackers need only low‑privileged network access; no elevated credentials are required to take over the framework.
OpenCVE Enrichment