Impact
The Oracle Call Center Technology product contains a vulnerability that permits an unauthenticated attacker with network access via HTTP to compromise the system. An attacker can execute the vulnerability to gain control and potentially take over the entire application. This results in full disclosure of confidential data, modification of data, and denial of legitimate availability.
Affected Systems
The affected product is Oracle Call Center Technology (part of Oracle E‑Business Suite) in versions 12.2.3 through 12.2.15. All deployments running any of these versions are susceptible if they are reachable over HTTP.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 indicates high severity, with full confidentiality, integrity, and availability impacts. The EPSS is not available and the vulnerability is not currently listed in CISA's KEV catalogue. Based on the description the attack vector is network access through HTTP. The lack of authentication requirement means any host that can reach the HTTP endpoint could exploit the flaw, making the risk significant for exposed deployments.
OpenCVE Enrichment