Impact
A vulnerability exists in the MWA Terminal Server component of Oracle Mobile Application Server. The flaw permits a low‑privileged attacker with network access via HTTP to gain unauthorized access to data stored by the server. The impact is confined to confidentiality, allowing the attacker to view or retrieve critical data that should be protected.
Affected Systems
Oracle Mobile Application Server (part of Oracle E‑Business Suite) versions ranging from 12.2.3 to 12.2.15 are affected. The Vulnerable component is the MWA Terminal Server exposed through HTTP endpoints.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates moderate severity with a confidentiality impact. The EPSS score of < 1% indicates a very low but nonzero exploitation probability, and the CVSS vector (AV:N, AC:L, PR:L, UI:N, S:U, C:H) suggests the vulnerability is easily exploitable by an attacker who is already a low‑privileged user on the network. The weakness is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack can be executed over the network without additional authentication.
OpenCVE Enrichment