Impact
An unauthenticated attacker who can reach the Oracle EDI Gateway over HTTP can exploit a flaw in the E-Business Suite’s EDI component. The vulnerability, rated CVSS 8.1, enables complete compromise of confidentiality, integrity, and availability, allowing the attacker to take control of the gateway and its data flows.
Affected Systems
The Oracle EDI Gateway component of Oracle E-Business Suite versions 12.2.3 through 12.2.15 is affected. Users deploying any of these releases need to verify whether the gateway is exposed to external networks.
Risk and Exploitability
The attack vector is network-based; the attacker requires only HTTP access and no user interaction. The high attack complexity reduces the likelihood of successful exploitation, and the EPSS score of less than 1% indicates a low probability of real‑world attacks. The vulnerability is not listed in CISA KEV, but its potential to expose the gateway to remote code execution remains a significant risk for exposed instances.
OpenCVE Enrichment