Impact
Vulnerability in Oracle Mobile Application Server (MWA Terminal Server) permits a high‑privileged attacker with network access via HTTP to compromise the service. Successful exploitation results in unauthorized access to critical data, full read and write access to all Oracle Mobile Application Server–accessible data, as well as the ability to update, insert or delete data, and to trigger a hang or repeatable crash (complete denial of service). The weakness is reflected in CWE‑284 (Access Control) and CWE‑400 (Resource Exhaustion).
Affected Systems
Oracle Mobile Application Server product of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, are affected.
Risk and Exploitability
The CVSS 3.1 Base score of 6.7 indicates moderate‑high risk with impacts to confidentiality, integrity and availability. The EPSS score of less than 1 % suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a high‑privileged attacker who can reach the service over HTTP. While the likelihood of exploitation is currently low, the potential impact warrants timely remediation.
OpenCVE Enrichment