Impact
The vulnerability resides in the ADPatch component of Oracle’s Applications DBA in Oracle E‑Business Suite. An attacker who gains local logon to the infrastructure where Applications DBA runs can exploit this flaw, requiring only a second human’s interaction to achieve full compromise. The impact includes loss of confidentiality, integrity, and availability—effectively a takeover of the applications database service. The weakness is documented by CVSS‑3.1 as AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, with a Base score of 7.8.
Affected Systems
Oracle Corporation’s Applications DBA product for Oracle E‑Business Suite, specifically the ADPatch component, in supported versions 12.2.3 through 12.2.15. Users operating any of these releases are affected by the flaw.
Risk and Exploitability
The CVSS severity is high (score 7.8) but the EPSS indicates < 1 % likely to see automated exploitation, and the vulnerability is not catalogued in the CISA KEV list. The flaw requires the attacker to have local access to the host and to rely on a third party to trigger the exploit, which limits but does not eliminate the threat, especially for environments with insufficient access controls or inadequate monitoring of administrative activity.
OpenCVE Enrichment