Impact
Oracle E‑Business Suite Applications DBA has a vulnerability that allows an attacker with low privileges and local system access to compromise the Applications DBA utility. The flaw can lead to a full takeover of Applications DBA. The vulnerability carries confidentiality, integrity, and availability impacts as reflected in its CVSS 3.1 base score of 7.8.
Affected Systems
Affected products are Oracle Corporation Applications DBA within Oracle E‑Business Suite. Supported versions susceptible to the flaw are 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS score is 7.8, indicating high severity. The EPSS score is less than 1%, suggesting the exploitation probability is currently very low, but that does not negate the need for remediation. The vulnerability is not listed in the CISA KEV catalog. Attack requires local infrastructure logon and the ability to execute code within the Applications DBA process. Once reached, the attacker can execute any operation with the same privileges as the DBA utility.
OpenCVE Enrichment