Impact
A flaw exists in the internal operations component of Oracle Call Center Technology that permits a low‑privileged attacker with network reachability over HTTP to compromise the system. Successful exploitation can lead to full takeover of the application, resulting in loss of confidentiality, integrity, and availability. This weakness allows unchecked access to privileged functions, effectively bypassing normal authorization controls.
Affected Systems
Oracle Call Center Technology versions 12.2.3 through 12.2.15 are affected. The product is integrated into Oracle E‑Business Suite and is typically deployed by organizations operating call center services.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates a high‑severity vulnerability with complete impacts on confidentiality, integrity, and availability. The EPSS score of < 1% reflects a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. However, the attack requires only low privileges and network connectivity to HTTP, making the attack vector likely remote network. Because a successful exploit enables a low‑privileged user to take full control of the system, the risk remains significant for exposed or inadequately protected deployments.
OpenCVE Enrichment