Impact
A flaw in the Oracle Application Object Library component, the AOL Generic Loader, allows an attacker who has already logged on to the infrastructure where this library executes to fully compromise it. The vulnerability results in confidentiality, integrity and availability impacts, as an attacker could effectively take control of the library. The CVSS 3.1 base score of 6.7 reflects a medium‑to‑high severity with local access and high privilege requirements.
Affected Systems
Oracle Corporation’s Oracle Application Object Library, part of the Oracle E‑Business Suite, is affected. Affected versions are 12.2.3 through 12.2.15. The vulnerability specifically involves the AOL Generic Loader component of the library.
Risk and Exploitability
The CVSS score of 6.7 indicates a moderate‑to‑high risk, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the current threat landscape. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a high‑privileged user who has access to the host infrastructure, implying that the attack vector is local, with high privileges. Successful exploitation could lead to a takeover of the Oracle Application Object Library and the data it manages.
OpenCVE Enrichment