Impact
This vulnerability allows an attacker who has low privileges and can reach the Oracle Alert system over HTTP to take over the application. Successful exploitation results in the attacker gaining control of the Oracle Alert instance, leading to full confidentiality, integrity, and availability loss for the affected components.
Affected Systems
Oracle Alert product of Oracle E‑Business Suite, specifically the Internal Operations component. Versions 12.2.3 through 12.2.15 are affected. No other vendors or products are listed.
Risk and Exploitability
The CVSS 3.1 score of 8.8 indicates a high‑severity flaw with low attack complexity and low privileges needed. The exploit is network‑based, used over HTTP, and can be performed by a low‑privileged user, making it likely that an attacker could discover and use the flaw quickly. The EPSS score of < 1 % suggests that automated exploitation activity is currently rare, but the flaw is still listed in the vendor’s security advisory and is not a known CISA KEV. Based on the vector and description, the vulnerability appears to be an improper access control flaw allowing authentication bypass or privilege escalation. The attack can be conducted remotely without user interaction, and the impact is complete compromise of the Oracle Alert service.
OpenCVE Enrichment