Impact
Vulnerability in Oracle Applications DBA internal operations component of Oracle E‑Business Suite, due to improper access control (CWE-284), allows a local attacker with low‑privileged access to the infrastructure where the DBA runs to compromise the DBA, potentially exposing all data that the DBA can access. The attack is deemed easily exploitable, with a CVSS v3.1 base score of 6.5 that affects confidentiality only.
Affected Systems
affected product is Oracle Applications DBA, part of Oracle E‑Business Suite, with versions 12.2.3 through 12.2.15 vulnerable. Systems running any of these releases and where the DBA is deployed locally are at risk, and the vulnerability can impact additional Oracle products due to the described scope change.
Risk and Exploitability
With a local attack vector, low attack complexity, and low privilege requirements, the EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog. However, because the exploit changes the security scope, an attacker who succeeds can reach higher‑level data or additional components. The CVSS score of 6.5 indicates moderate severity, but the potential for widespread data exposure warrants immediate attention.
OpenCVE Enrichment