Impact
A flaw in the AD Utilities component of Oracle E‑Business Suite’s Applications DBA allows a high‑privileged attacker who can reach the service over HTTP to compromise the Applications DBA service. Successful exploitation can lead to full control over the database management service, resulting in loss of confidentiality, integrity, and availability for the underlying database.
Affected Systems
Oracle Corporation’s Applications DBA product is vulnerable in the 12.2.3 through 12.2.15 releases. Systems running any of these versions without the official patch are at risk.
Risk and Exploitability
The CVSS 3.1 base score of 7.2 signals a high severity bug with complete confidentiality, integrity, and availability impacts. The EPSS score of < 1% indicates a very low current probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the vendor’s description, the likely attack vector is a network‑based HTTP request; the flaw requires the attacker to have high privileges on the target system to exploit the remote interface and drain administrative control.
OpenCVE Enrichment