Impact
The vulnerability resides in the Attachments / File Upload component of the Oracle E‑Business Suite's Application Object Library exploit the component over HTTP to upload and execute code in the context of the Application Object Library. If successful, the attacker can take full control of the library, compromising confidentiality, integrity and availability of the system.
Affected Systems
Affected are Oracle Corporation's Oracle Application Object Library product, versions 12.2.3 through 12.2.15 of the Oracle E‑Business Suite. These releases are specified as at risk by Oracle.
Risk and Exploitability
The CVSS base score of 8.8 classifies the flaw as high severity. The EPSS score is below 1 % and the vulnerability is not currently listed in the CISA KEV catalog, indicating a low current exploitation probability. The attack vector is through a normal HTTP request and only requires low privileged access; no user interaction is needed. Successful exploitation can lead to a complete takeover of the library, making risk management critical.
OpenCVE Enrichment