Impact
A vulnerability exists in Oracle Call Center Technology, part of Oracle E‑Business Suite, which allows a low‑privileged attacker with network access via HTTP to gain unauthorized access to critical data or obtain complete access to all Call Center Technology data. This flaw also permits unauthorized update, insert or delete operations on the data, causing both confidentiality and integrity impacts.
Affected Systems
Oracle Call Center Technology versions 12.2.3 through 12.2.15 are affected. Systems running these releases, particularly those with the Internal Operations component exposed over HTTP, are at risk. The impact may extend to other Oracle E‑Business Suite products if the configuration scope changes.
Risk and Exploitability
The CVSS v3.1 score of 8.5 reflects high severity, driven primarily by a high confidentiality impact and a low integrity impact with a changed scope. Exploitation is considered easy because the attacker only needs low privileges and HTTP access to the exposed component. The EPSS score of < 1% indicates a very low exploitation probability, so real‑world exploitation is unlikely at this time, although the high severity warrants immediate attention.
OpenCVE Enrichment