Impact
A flaw in the RapidClone command‑line component of Oracle Applications Manager allows an attacker with local infrastructure access to compromise the Application Manager. The vulnerability can lead to a complete takeover of the application, impacting confidentiality, integrity, and availability.
Affected Systems
Oracle Corporation’s Oracle Applications Manager, a component of Oracle E‑Business Suite, is affected. Versions 12.2.3 through 12.2.15 contain the RapidClone flaw. These are the only installed releases documented as impacted by the advisory.
Risk and Exploitability
The attacker must have local host access to the infrastructure where Oracle Applications Manager runs. Once that foothold is achieved, the exploit permits takeover of the Application Manager. The EPSS score of less than 1% indicates a low likelihood of exploitation in the wild, and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog. Nonetheless, the high CVSS base score of 8.4 and the ability to take over the application make this a significant risk that can only be mitigated by patching or disabling the vulnerable interface.
OpenCVE Enrichment