Impact
This vulnerability allows a high privileged attacker with network access via HTTP to compromise the Oracle iSupport component of Oracle E‑Business Suite. Successful exploitation can result in full takeover of the iSupport service, exposing confidential operational data and compromising the confidentiality, integrity, and availability of the affected system.
Affected Systems
Oracle Corporation’s Oracle iSupport component of Oracle E‑Business Suite is affected for versions 12.2.3 through 12.2.15. These versions provide internal operations and support functions accessed over HTTP.
Risk and Exploitability
The CVSS 3.1 base score of 6.6 indicates significant impact on confidentiality, integrity, and availability, while the EPSS score of less than 1 % suggests a low likelihood of widespread exploitation at present. Because the flaw requires a high privileged attacker to reach the iSupport HTTP endpoint, the practical attack vector is limited. The vulnerability is not listed in the CISA KEV Catalog, but if exploited the attacker could achieve full control over the iSupport service, compromising confidentiality, integrity, and availability.
OpenCVE Enrichment