Impact
The vulnerability is in Oracle Applications Manager’s RapidClone command-line tool, allowing a low‑privileged local user to compromise the entire installation and gain unauthorized creation, deletion or modification of critical data, thereby affecting confidentiality and integrity. The CVSS v3.1 base score of 7.1 reflects high confidentiality and integrity impact.
Affected Systems
Oracle Corporation’s Oracle Applications Manager product, versions 12.2.3 through 12.2.15, is affected. The flaw is confined to the RapidClone component, but any deployment of these versions is at risk.
Risk and Exploitability
The flaw is local, requiring only low privileges and no user interaction, which makes exploitation straightforward for an attacker with host access. The CVSS score of 7.1 classifies it as high severity; however, the EPSS score of less than 1 % indicates a very low probability of exploitation at this time, and it is not listed in the CISA KEV catalog. Prompt mitigation is essential to prevent potential data loss or system compromise.
OpenCVE Enrichment