Impact
A vulnerability in the Oracle Applications Framework component known as Web Utilities allows a high‑privileged attacker with network access over HTTP to fully compromise the framework. The flaw is an access control failure (CWE‑284) that can be easily exploited. Successful exploitation destroys confidentiality, integrity and availability, effectively enabling a complete takeover of the affected system and potentially impacting additional Oracle products due to scope change.
Affected Systems
The flaw affects Oracle Applications Framework users of Oracle E‑Business Suite. Supported versions from 12.2.8 through 12.2.15 are vulnerable. The vulnerability resides exclusively in the Web Utilities component of this product.
Risk and Exploitability
The CVSS score of 9.1 indicates a critical severity. Although the EPSS score is below 1%, the risk remains high because a remote attacker could leverage the flaw if they possess high‑level privileges and network reachability. The flaw is not yet listed in the CISA KEV catalog, but its impact warrants immediate attention. Exploitation requires network access to the exposed HTTP interface and the presence of a privileged account; no special conditions beyond these are specified.
OpenCVE Enrichment