Impact
The vulnerability exists in the Internal Operations component of Oracle Applications DBA, where an attacker with low privileges who can reach the system over HTTP may exploit a flaw that allows them to bypass normal access controls. As a result the attacker can read or modify sensitive database information and can trigger a partial denial of service. The weakness results in a confidentiality impact rated high and a partial availability impact.
Affected Systems
Oracle Corporation’s Oracle Applications DBA product in Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The CVSS 3.1 base score of 7.1 reflects the severity of the flaw. Exploitation is considered easy with available network access via HTTP and does not require elevated privileges. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog. Attackers can gain unauthorized read or write access to all data exposed by the DBA component and can produce a measurable impact on availability by disrupting service availability. The attack requires only network connectivity and low user privileges, making the risk significant for organizations that expose the DBA interface to untrusted networks.
OpenCVE Enrichment