Impact
This vulnerability resides in the Oracle Mobile Application Server component MWA General Bugs. It exploits improper access control (CWE-284), allowing an attacker with network access through HTTP to gain high privileges and complete control over the server. The flaw leads to confidentiality, integrity, and availability violations, permitting the adversary to execute arbitrary code, alter data, and disrupt services. The CVSS vector reflects a high severity (7.2) due to the need for network access, low attack complexity, high privileges, and no user interaction.
Affected Systems
Oracle Mobile Application Server versions from 12.2.3 through 12.2.15 are impacted. The issue is specific to the MWA General Bugs component of Oracle E‑Business Suite.
Risk and Exploitability
The CVSS base score of 7.2 classifies the vulnerability as high, yet the EPSS score of less than 1% signals a very low probability of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog. Attackers would need a network route to the server’s HTTP interface, making the exploit remote but confined to those who can reach that interface. Because high privileges are obtained, the potential damage to an organization is significant if an attacker gains this access.
OpenCVE Enrichment