Impact
Vulnerability in Oracle Applications Platform Engineering's Valid Session component permits an unauthenticated attacker with network access over Oracle Net to compromise the platform. Successful exploitation can lead to full takeover, affecting confidentiality, integrity and availability of the application.
Affected Systems
Oracle E‑Business Suite component Oracle Applications Platform Engineering, with supported versions from 12.2.3 to 12.2.15.
Risk and Exploitability
The flaw has a CVSS 3.1 base score of 8.1, indicating high severity. The EPSS score is less than 1%, indicating a very low probability of exploitation, but the absence of credential or UI requirements means the vulnerability can be leveraged remotely and without privilege, making it attractive to attackers. The vulnerability is not listed in the CISA KEV catalog, but its impact and network exposure warrant immediate attention.
OpenCVE Enrichment