Impact
The vulnerability in Oracle Marketing, component Audience, is highly exploitable by an attacker with allows the attacker to compromise the application over HTTP, potentially leading to a full takeover of the Marketing system. The impact includes loss of confidentiality, integrity and availability, as reflected in the CVSS vector.
Affected Systems
Oracle Marketing (Audience component) versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The CVSS 3.1 base score of 7.2 indicates a high risk, yet the EPSS score of less than 1% shows the current probability of exploitation is low. The flaw is not listed in the CISA KEV catalog. The attack vector is network-based via HTTP and requires an attacker to possess high privileged credentials to successfully exploit the vulnerability.
OpenCVE Enrichment