Impact
A vulnerability in Oracle EDI Gateway, arising from improper access control (CWE-284), allows a high‑privileged attacker with network access over HTTP to take control of the gateway, enabling full compromise of confidentiality, integrity, and availability.
Affected Systems
Oracle EDI Gateway, part of Oracle E‑Business Suite, affected versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS base score is 7.2, indicating high impact when exploited. The EPSS score is below 1 % and the issue is not listed in CISA’s KEV catalog, suggesting a low current exploitation likelihood, but the potential impact is severe. The attack vector is network‑based via HTTP and requires a privileged attacker, making the vulnerability highly exploitative if the gateway is exposed to untrusted networks.
OpenCVE Enrichment