Impact
A vulnerability in Oracle Applications Manager allows an attacker with low privileges but network connectivity through HTTPS to compromise the system. The flaw results in full control of Oracle Applications Manager, enabling the attacker to execute arbitrary commands, modify configuration, and exfiltrate sensitive data. The impact covers confidentiality, integrity, and availability, signifying a complete takeover of the affected application.
Affected Systems
Oracle Corporation’s Oracle Applications Manager within Oracle E‑Business Suite, specifically the Oracle Diagnostics Interfaces component. The affected releases are 12.2.3 through 12.2.15. Systems running any of these versions with external or internalHTTPS access remain vulnerable.
Risk and Exploitability
The CVSS 3.1 Base Score of 8.8 indicates a high severity, with the vector pointing to network‑reachable, authenticated low‑priv, integrity, and availability compromise. The EPSS score of less than 1 % suggests that the explosive probability is currently low, but the lack of a CISA KEV listing does not diminish the need for immediate mitigation. The attack vector is inferred to be HTTPS‐based network traffic, requiring network access but not privileged credentials.
OpenCVE Enrichment