Impact
The flaw resides in the ADPatch component of Oracle’s Applications DBA for Oracle E‑Business Suite. It is a CWE‑284 Weak Authentication or Authorization weakness that lets an attacker who can log onto the host where Applications DBA runs gain control of the service. Because the vulnerability requires the attacker to act locally, it cannot be exploited remotely, but it can result in full takeover of the database administration functions. The description indicates that a second person’s action is necessary to trigger the exploit; it can be inferred that a human with local access must perform a manual step to activate the vulnerability.
Affected Systems
Oracle Corporation’s Applications DBA product, specifically the ADPatch component, is affected in supported Oracle E‑Business Suite releases 12.2.3 through 12.2.15. Users running any of these versions are exposed to the flaw.
Risk and Exploitability
The CVSS 3.1 base score of 7.8 reflects a high severity local privilege escalation. The EPSS score is below 1 %, indicating a low probability of automated exploitation. The vulnerability is not listed in the CISA KEV catalog. Because exploitation requires local logon rights and a third‑party action to activate the flaw, the risk is moderated by the need for privileged access; however, any environment with insufficient local access controls remains vulnerable.
OpenCVE Enrichment