Impact
A weakness in Oracle Call Center Technology permits a low‑privileged attacker with network access over HTTP to compromise the Internal Operations component. Successful exploitation can lead to full takeover of the service, impacting confidentiality, integrity, and availability. The specific vulnerability type is not fully described but is inferred to involve an authentication or authorization flaw, given the reference to unauthenticated HTTP access.
Affected Systems
Oracle Call Center Technology versions 12.2.3 through 12.2.15 within Oracle E‑Business Suite are affected. No other vendors or products are listed.
Risk and Exploitability
A CVSS 3.1 base score of 8.8 indicates high severity. The attack vector is network, with low attack complexity and low privileges, making exploitation easily feasible. The EPSS score is below 1%, suggesting low current exploitation probability. The vulnerability is not recorded in the CISA KEV catalog. The likely exploit path is unauthenticated HTTP requests to the service, implying anyone with network reach can attempt the attack.
OpenCVE Enrichment