Impact
A vulnerability in the Web Utilities component of Oracle Applications Framework allows an attacker with low privileges and network access over HTTP to compromise the application framework. The flaw can lead to a full takeover, resulting in complete loss of confidentiality, integrity, and availability for the affected system. The weakness originates from insufficient authorization checks, reflected in CWE‑269, CWE‑284, CWE‑287, and CWE‑306.
Affected Systems
Oracle Applications Framework for Oracle E‑Business Suite; versions 12.2.11 through 12.2.15 are affected.
Risk and Exploitability
The CVSS v3.1 score of 8.8 indicates high severity, while an EPSS score of less than 1% signifies a very low but non‑zero likelihood of exploitation in the wild. The vulnerability is not currently listed in CISA’s KEV catalog, indicating no confirmed large‑scale exploitation. Attackers typically exploit the flaw over HTTP without requiring elevated privileges, making network‑side defenses and patching critical.
OpenCVE Enrichment