Impact
This vulnerability in Oracle Call Center Technology enables a high‑privileged attacker with network connectivity to the HTTP interface to compromise the system. The flaw is exploitable by an attacker with high privileges, can be used to achieve a full takeover, and results in the loss of confidentiality, integrity, and availability of the affected software. The CVSS 3.1 base score of 7.2 reflects a moderate severity capable of producing complete system compromise.
Affected Systems
Oracle Call Center Technology versions 12.2.3 through 12.2.15 are affected. The risk applies to installations that expose the Internal Operations service over HTTP and to environments where the service is reachable from the network.
Risk and Exploitability
The EPSS score of 0.00499 indicates a very low probability of exploit at this time, though the vulnerability remains high impact. Since the issue is not listed in CISA KEV, no public exploit has yet been identified. The attack likely involves sending crafted HTTP requests to the vulnerable component, taking advantage of the privilege configuration to elevate or maintain control beyond the intended scope.
OpenCVE Enrichment