Impact
Oracle Applications DBA, a component of Oracle E-Business Suite, contains a difficult-to-exploit flaw in its JRI and Java utilities that allows an unauthenticated attacker who can reach the service over HTTP to compromise the application. The vulnerability is a weakness in authentication (CWE-284) that, if successfully triggered, can lead to full takeover of the Oracle Applications DBA, affecting confidentiality, integrity, and availability. The flaw requires the presence of a human user to interact with the attacker’s request; the attacker cannot complete the exploit without that user involvement.
Affected Systems
Oracle Corporation’s Oracle Applications DBA (Oracle E‑Business Suite) versions 12.2.3 through 12.2.15 are affected. The issue is present in the JRI and other Java utility components of the product and is applicable to all installations that expose the HTTP interface without proper authentication.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 indicates a high‑impact vulnerability. The vector specifies that the attack requires network access over HTTP (AV:N), has a high attack complexity (AC:H), no privileges (PR:N), and user interaction (UI:R), indicating that while the flaw is serious, it is not easily exploitable by an automated attacker. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, yet the potential for a complete application takeover warrants prompt action.
OpenCVE Enrichment