Impact
The vulnerability lies in the RapidClone command‑line tool of Oracle Applications Manager. It allows a low‑privileged local user to exploit a misconfigured privilege check and take full control of the Applications Manager installation. Successful exploitation leads to unauthorized creation, deletion, or modification of critical data, thereby compromising confidentiality and integrity. The weakness is tied to improper permission checks (CWE-284) and is quantified by a CVSS v3.1 Base Score of 7.1 with high confidentiality and integrity impact.
Affected Systems
Oracle Corporation’s Oracle Applications Manager product, versions 12.2.3 through 12.2.15, is affected. The vulnerability is confined to the RapidClone component, but any deployment of these versions exposes the installation to the threat.
Risk and Exploitability
The flaw is local and requires only low privileges, with no user interaction. This makes exploitation straightforward for an attacker who has host access. The CVSS score of 7.1 classifies the issue as high severity, although the EPSS score of less than 1 % indicates a very low probability of exploitation at this time, and it is not listed in the CISA KEV catalog.
OpenCVE Enrichment