Impact
A vulnerability in Oracle Applications Manager’s RapidClone command‑line component allows an unauthenticated attacker who has already logged onto the host to execute privileged commands, resulting in a complete takeover of the manager. This flaw delivers confidentiality, integrity, and availability compromise in a single exploit, as an attacker can read, modify, and disrupt Application Manager data and operations. The CVSS v3.1 vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H yields a high 8.4 base score, highlighting its severity.
Affected Systems
Vendor Oracle issues this flaw for the Oracle E‑Business Suite product Oracle Applications Manager, affecting versions 12.2.3 through 12.2.15 inclusive. These are the only documented deployments impacted by the RapidClone component vulnerability.
Risk and Exploitability
With an AV:L score, the attack requires the attacker to be present on the network and to be able to log onto the host where the manager runs. The current EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. However, once the prerequisite host access is achieved, the attacker can elevate privileges within the Oracle Applications Manager application, potentially bypassing all user controls. Because the vulnerability affects core command‑line functionality, patching is the only definitive mitigation.
OpenCVE Enrichment