Impact
An easily exploitable flaw in Oracle Call Center Technology allows a high privileged attacker with network access via HTTP to compromise the system. Successful exploitation can lead to a complete takeover, compromising confidentiality, integrity, and availability of the affected software. The vulnerability is classified as a high severity remote code execution risk.
Affected Systems
Oracle Corporation’s Call Center Technology component of Oracle E‑Business Suite is affected. Versions 12.2.3 through 12.2.15 are vulnerable. The impact applies to deployments that expose the Internal Operations service over HTTP.
Risk and Exploitability
The CVSS 3.1 base score of 7.2 reflects a moderately high likelihood of exploitation for attackers who can reach the HTTP interface, with a low attack complexity but requiring high privileges. Because EPSS is not available, the current exploit probability is unknown, and the vulnerability is not yet listed in the CISA KEV catalog. The attack path is inferred to involve direct HTTP requests to the vulnerable component, leveraging an authentication or privilege misuse flaw to gain full control.
OpenCVE Enrichment