Impact
The vulnerability in Oracle Report Manager allows a low‑privileged attacker with network access over HTTPS to compromise the application. An attacker can take full control of Oracle Report Manager, gaining confidentiality, integrity, and availability for the affected system. The weakness is improper authentication and privilege escalation, classified as CWE-284, and is quantified by a CVSS 3.1 base score of 8.8.
Affected Systems
Oracle Report Manager, part of Oracle E‑Business Suite, affects the 12.2.x series from version 12.2.3 through 12.2.15. All installations of these versions that expose the HTTPS interface are susceptible to the vulnerability.
Risk and Exploitability
The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates that the attack can be performed by a network adversary with low privileges and no user interaction. The EPSS score of <1% suggests a low current exploitation likelihood, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the high severity score and potential for full application takeover warrant prompt remediation.
OpenCVE Enrichment