Impact
The vulnerability in Oracle Interaction Blending permits a high‑privileged attacker with network access via HTTP to fully take control of the component. The flaw is described as easily exploitable, resulting in loss of confidentiality, integrity, and availability for the service and any data handled by it. This vulnerability is found in the Oracle E‑Business Suite’s Internal Operations module and grants the attacker broad privileges on the affected system.
Affected Systems
Oracle Interaction Blending versions 12.2.3 through 12.2.15, part of the Oracle E‑Business Suite, are affected. The component resides within the Internal Operations module and is distributed by Oracle Corporation. These product versions lack a fix until patched or removed.
Risk and Exploitability
The CVSS 3.1 score of 7.2 reflects high severity with network (AV:N) and low attack complexity (AC:L). The EPSS score of < 1% indicates a low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Successful exploitation requires network connectivity to the HTTP endpoints of Interaction Blending and a high‑privileged attacker credential.
OpenCVE Enrichment