Impact
A vulnerability in Oracle Application Object Library allows an unauthenticated attacker with network access through HTTP to create, delete, or modify critical data, or to gain unauthorized access to all accessible data. This can lead to alteration or theft of sensitive information without requiring user interaction or elevated privileges, representing a significant breach of confidentiality and integrity. The weakness is classified as CWE‑284, an improper access control vulnerability.
Affected Systems
The affected products are Oracle Corporation’s Oracle Application Object Library component of Oracle E-Business Suite, versions 12.2.3 through 12.2.15. These versions are included in the Oracle Application Object Library product line and are reachable via standard HTTP interfaces.
Risk and Exploitability
The CVSS v3.1 base score of 7.4 indicates high severity with substantial confidentiality and integrity impacts. The EPSS score of less than 1% suggests that the likelihood of exploitation is low, and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector requires only network access via HTTP and no authentication, making it theoretically possible to exploit remotely by sending crafted HTTP requests to the vulnerable component. In practice, the need for network reachability to the target suggests a moderate to low exploitation risk, though the potential damage is high.
OpenCVE Enrichment