Impact
The vulnerability resides in the Message Component of Oracle Email Center. An unauthenticated attacker able to reach the component over HTTP can, with user interaction, obtain or modify sensitive data exposed by the Email Center. The flaw permits a change to the security scope, meaning that a breach of Email Center could extend to other Oracle E‑Business Suite products, increasing the potential impact.
Affected Systems
Oracle Email Center versions 12.2.3 through 12.2.15 are affected. These are part of Oracle E‑Business Suite and can be accessed through standard HTTP interfaces.
Risk and Exploitability
The CVSS v3.1 score of 8.2 indicates a high severity vulnerability. The attack vector is network‑based over HTTP and requires low effort but also requires user interaction – the victim must click a malicious link or otherwise execute a payload. No EPSS score is available, and the vulnerability is not listed in CISA KEV, suggesting no known public exploits yet. Nonetheless, the high CVSS and scope change raise the risk, and the flaw remains exploitable for attackers who can coerce or trick users.
OpenCVE Enrichment