Impact
An easily exploitable flaw exists in the Audience component of Oracle Marketing that allows a remote attacker with only network access via HTTP to achieve full takeover. The vulnerability can be leveraged by a low‑privileged user and results in catastrophic loss of confidentiality, integrity, and availability, with a CVSS 3.1 Base Score of 8.8.
Affected Systems
Oracle Marketing, part of Oracle E‑Business Suite, Audience component versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The high CVSS score indicates severe potential impact, while the EPSS score of less than 1% suggests the likelihood of exploitation is currently low, and the issue has not yet been recorded in the CISA KEV catalog. The attack vector is remote via HTTP, requiring only low privilege to execute, which can lead to complete application compromise if successful.
OpenCVE Enrichment