Impact
A flaw within the Oracle Applications DBA component of Oracle E‑Business Suite’s Internal Operations allows an attacker who already possesses high‑level privileges to remotely access the DBA service over HTTP and seize control of the process. The vulnerability stems from improper privilege checks and is identified as CWE‑269 (Improper Privilege Management). Successful exploitation can result in complete takeover of the DBA, granting the attacker the same high‑privilege level as the affected user, thereby enabling read, write, or delete operations on sensitive configuration and business data, as well as the potential to disrupt related services.
Affected Systems
The vulnerability affects Oracle Applications DBA versions 12.2.3 through 12.2.15 in Oracle E‑Business Suite, released by Oracle Corporation. The relevant product component is Internal Operations within the DBA service.
Risk and Exploitability
The CVSS v3.1 base score of 7.2 indicates a moderate to high severity, with coupled impacts on confidentiality, integrity, and availability. The EPSS score of less than 1% suggests a relatively low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. An attacker must be able to reach the HTTP endpoint from the network and already have high‑level credentials; once those prerequisites are satisfied, the flaw can be used to remotely compromise the DBA process without user interaction.
OpenCVE Enrichment