Impact
The vulnerability resides in the Attachments / File Upload component of Oracle Application Object Library in Oracle E‑Business Suite. An attacker with only low privileges and network access to the HTTP interface can upload malicious files that are then executed with the privileges of the library service, allowing the attacker to fully compromise the application, jeopardizing confidentiality, integrity, and availability of the system.
Affected Systems
Oracle Corporation’s Oracle Application Object Library product, versions 12.2.3 through 12.2.15, is affected.
Risk and Exploitability
The flaw has a CVSS 3.1 base score of 8.8, indicating high severity, while the EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low current exploitation probability. The attack vector is through a standard HTTP request and requires only low privileged access with no user interaction; successful exploitation would grant the attacker full control of the library.
OpenCVE Enrichment