Impact
A flaw in the AR Web Utilities component of Oracle iReceivables allows an unauthenticated attacker to compromise the application, potentially taking full control and affecting confidentiality, integrity, and availability. The high CVSS score of 8.1 indicates severe impact.
Affected Systems
Oracle iReceivables, part of Oracle E‑Business Suite, is affected for supported versions 12.2.3 through 12.2.15. The issue targets the AR Web Utilities component within this product range.
Risk and Exploitability
The CVSS score of 8.1 denotes severe impact, while the EPSS score of less than 1 % signals that exploitation in the wild is currently uncommon. Because the flaw is accessed over the network, an attacker only needs connectivity to the AR Web Utilities HTTP interface; the pathway requires high attack complexity and no user interaction, yet once leveraged it can lead to a complete takeover. The vulnerability is not listed in the CISA KEV catalog, indicating no documented widespread exploitation.
OpenCVE Enrichment