Impact
The Oracle Application Object Library contains a flaw that allows a low‑privileged attacker with network access to the HTTP interface to take full control of the component. The vulnerability resides in the DB Privileges functionality, enabling an attacker to compromise confidentiality, integrity, and availability of the Application Object Library.
Affected Systems
Oracle Corporation’s Oracle Application Object Library, part of Oracle E‑Business Suite, is affected for versions 12.2.3 through 12.2.15. Only installations that expose the HTTP interface are vulnerable.
Risk and Exploitability
The CVSS base score of 7.5 indicates high impact with moderate difficulty to exploit, while an EPSS score of less than 1% suggests a low real‑world attack likelihood. The flaw is not listed in the CISA KEV catalog. Exploitation requires remote access via HTTP and low privileges; the attacker can then gain full control over the Application Object Library, potentially leading to data loss, tampering, or lateral movement within the environment.
OpenCVE Enrichment