Impact
A flaw in the Oracle Installed Base component of Oracle E‑Business Suite allows a low‑privileged attacker with network access via HTTP to acquire full control of the system. Successful exploitation results in complete takeover, compromising confidentiality, integrity and availability of the installed product.
Affected Systems
Oracle E‑Business Suite Oracle Installed Base versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The issue carries a CVSS 3.1 score of 8.8, indicating high severity. The EPSS score is <1%, suggesting exploitation is currently unlikely but not impossible. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the attacker must have network access to the HTTP interface; no special user privileges beyond low are required to launch the attack.
OpenCVE Enrichment