Impact
Oracle XML Gateway’s install component has a weakness that allows a low‑privileged attacker with network access over HTTP to gain unauthorized access to all data exposed by the gateway and may cause a partial denial of service. The flaw stems from inadequate access control (CWE‑284) and results in high confidentiality impact and low availability impact, reflected in a CVSS 3.1 base score of 7.1.
Affected Systems
Oracle XML Gateway, versions 12.2.3 through 12.2.15 are affected. The vulnerability is specific to the install component of Oracle E‑Business Suite and applies to all builds within this range.
Risk and Exploitability
The CVSS of 7.1 indicates moderate‑to‑high risk, while the EPSS score of less than 1% suggests a low current probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker only requires HTTP connectivity to the gateway; no special privileges or user interaction are needed. By sending a crafted HTTP request the attacker can retrieve sensitive data or disrupt services, but the impact is confined to the XML Gateway rather than a full system compromise.
OpenCVE Enrichment