Impact
This vulnerability affects Oracle iSetup, a component of Oracle E‑Business Suite’s General Ledger Update Transform and Reports. It allows an attacker who has low‑privileged network access over HTTP to compromise the iSetup service and take full control of the application. Successful exploitation results in confidentiality, integrity, and availability impacts due to the complete takeover of the service.
Affected Systems
Oracle iSetup versions 12.2.3 through 12.2.15 are impacted. These releases are distributed by Oracle Corporation within Oracle E‑Business Suite deployments.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 classifies the issue as high severity. The attack vector requires network access (AV:N), a high effort level (AC:H), and low privilege (PR:L), with no user interaction required (UI:N). The EPSS score of less than 1% indicates a very low current exploitation likelihood, and the vulnerability is not listed in the CISA KEV catalog. Despite the low exploitation probability, the flaw permits complete takeover of iSetup with minimal prerequisites, making it a potential threat for exposed environments.
OpenCVE Enrichment