Impact
A vulnerability has been identified in the Oracle Applications Manager component known as Command Line – RapidClone. An attacker who already possesses high‑level privileges and can reach the system through the HTTP interface could trigger this flaw, allowing them to fully compromise the Applications Manager instance. The flaw would enable an operator to alter confidentiality, integrity and availability settings, effectively taking over the application. The CVSS 3.1 vector (AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H) reflects this remote impact.
Affected Systems
The affected product is Oracle Corporation’s Oracle Applications Manager, part of Oracle E‑Business Suite. Versions from 12.2.3 through 12.2.15 inclusive are impacted. The vulnerability is present within the Command Line – RapidClone feature of these releases.
Risk and Exploitability
The base CVSS score of 8.0 indicates high severity. The EPSS score is below 1%, suggesting that active exploitation is unlikely but not impossible. Because the flaw can be leveraged by a privileged insider or malicious actor with network access, the risk is significant for any organization that runs these versions on exposed networks. It is not currently listed in the CISA KEV catalog, but the potential for full system takeover warrants immediate attention.
OpenCVE Enrichment