Impact
A flaw in the RapidClone command line component of Oracle Applications Manager allows an attacker with network access over HTTP to gain unauthorized access to all data that the application manages. The vulnerability has no authentication requirement and can be exploited directly from the network, resulting in potential disclosure of highly confidential information.
Affected Systems
Oracle Applications Manager versions 12.2.3 through 12.2.15, inclusive. The flaw applies to the RapidClone command line interface exposed via the HTTP interface of the product.
Risk and Exploitability
The CVSS 3.1 score is 7.5, indicating a high risk to confidentiality with no impact on integrity or availability. The EPSS score of < 1% suggests a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the flaw by sending specially crafted HTTP requests to the RapidClone endpoint, enabling them to enumerate or retrieve sensitive data without requiring credentials.
OpenCVE Enrichment