Impact
The vulnerability resides in the Oracle Application Object Library component of Oracle E‑Business Suite and is an authorization flaw (CWE‑284). It permits a low‑privileged attacker who can reach the service over HTTP to compromise the application and ultimately take it over. Successful exploitation would compromise confidentiality, integrity, and availability, allowing the attacker to control the application and potentially access sensitive data.
Affected Systems
Affected versions of the Oracle Application Object Library are 12.2.3 through 12.2.15. The vulnerability applies to the Core component of the product.
Risk and Exploitability
The CVSS 3.1 Base Score of 7.5 indicates a high severity attack that could fully compromise the system. The EPSS score of less than 1% suggests that the exploitation rate is currently low, but the lack of listing in the CISA KEV catalog does not mitigate the risk of a targeted breach. Attackers would need network access to the HTTP interface and low privilege credentials to launch the exploit, after which the application can be fully taken over.
OpenCVE Enrichment