Impact
A vulnerability in Oracle Process Manufacturing Process Execution allows a low‑privileged attacker with network access to the system’s HTTP interface to compromise the application’s confidentiality, integrity, and availability. Successful exploitation can result in full takeover of the Oracle Process Manufacturing Process Execution component. The impact was measured with a CVSS 3.1 base score of 7.5, reflecting high impacts on confidentiality, integrity, and availability.
Affected Systems
Oracle Process Manufacturing Process Execution version 12.2.15 is affected. No other versions or products were listed as impacted in the CNA data.
Risk and Exploitability
The CVSS score of 7.5 indicates a medium‑to‑high severity. The EPSS score of less than 1 % suggests exploited instances are expected to be scarce at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over the public or internal network via HTTP, and an attacker with low privileges can exploit the flaw to execute code or achieve privilege escalation within the application.
OpenCVE Enrichment