Impact
An exploited flaw in the Configuration component of Oracle Applications Technology Stack allows a local, high-privileged attacker who can log in to the underlying infrastructure to create, delete, or modify critical data, or obtain complete access to all data managed by the stack. This results in both confidentiality and integrity loss for the data that the attacker can read or alter.
Affected Systems
Oracle Applications Technology Stack, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS score of 5.7 indicates moderate severity, and the EPSS score of less than 1 % shows a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV, and the exploit requires local administrative access, meaning only users who can log on to the host environment can potentially exploit it.
OpenCVE Enrichment