Impact
A remotely exploitable vulnerability in Oracle Report Manager allows an attacker with low privileges and network access via HTTP to compromise the application. Successful exploitation can lead to full takeover, exposing the confidentiality, integrity, and availability of the system. The weakness, classified under CWE-284, enables unauthorized access and manipulation of the Report Manager by bypassing proper access controls and input validation.
Affected Systems
The vulnerability affects Oracle Corporation's Oracle Report Manager component of Oracle E-Business Suite, specifically versions 12.2.3 through 12.2.15. Users of these versions who run Report Manager over HTTP and can be reached from a network are at risk.
Risk and Exploitability
The CVSS 3.1 base score is 8.8, indicating high severity. With an EPSS score of less than 1% and no listing in CISA KEV, the likelihood of widespread exploitation is low, yet the impact is severe. The attack vector requires network access, low attack complexity, and low privileges, suggesting that an attacker does not need administrative credentials to succeed.
OpenCVE Enrichment