Impact
The flaw resides in the Framework component of Oracle Fusion Middleware Control and allows a low privileged attacker with network access via HTTP to compromise the control interface. Successful exploitation can result in a full takeover of the system, compromising confidentiality, integrity, and availability. The CVSS 3.1 base score of 8.8 indicates a high severity rating with high impact on all three security objectives.
Affected Systems
Oracle Fusion Middleware Control versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability is present in the Framework component of these releases.
Risk and Exploitability
The vulnerability is network‑based (AV:N) and requires only low privileges (PR:L). The EPSS score is below 1 %, indicating a low but non‑zero probability of exploitation. It is not listed in CISA’s KEV catalog. The CVSS 3.1 base score of 8.8 indicates a high severity rating, highlighting significant impact on confidentiality, integrity, and availability. The advisory indicates that attackers with low privileges and network access via HTTP can compromise Oracle Fusion Middleware Control, but the specific HTTP endpoint or request type is not described in detail; therefore the precise attack path is not stated by Oracle.
OpenCVE Enrichment