Impact
This vulnerability in Oracle Applications Manager’s RapidClone command line component permits a high‑privilege attacker with network access via HTTP to take over the Applications Manager instance. The flaw falls under CWE‑284 (Improper Access Control) and can lead to full compromise of confidentiality, integrity, and availability.
Affected Systems
Affected versions span Oracle Applications Manager 12.2.3 through 12.2.15, part of Oracle E‑Business Suite. The product is supplied by Oracle Corporation.
Risk and Exploitability
The CVSS v3.1 base score of 8.0 signals high severity. The EPSS value of less than 1 % indicates a low probability of active exploitation at present, yet the potential for complete system takeover remains serious. The vulnerability is not listed in CISA KEV, but add‑on scope changes could impact other Oracle products if the compromise is achieved.
OpenCVE Enrichment