Impact
The vulnerability originates from a Java Server issue in Oracle One-to-One Fulfillment, allowing an unauthenticated attacker to compromise the application through an HTTP request. Successful exploitation grants the attacker full control over the system, enabling alteration of data, execution of arbitrary code, and potential disruption of all business processes. The weakness leads to complete loss of confidentiality, integrity, and availability for the compromised instance.
Affected Systems
The-One Fulfillment, part of Oracle E‑Business Suite, for all supported versions from 12.2.3 through 12.2.15. The vulnerability is tied to the Java Server component, which processes incoming HTTP requests. No other vendors or products are listed.
Risk and Exploitability
The CVSS base score of 8.1 indicates a high severity. The exploit requires only network access over HTTP with no user credentials, and the attack complexity is high, meaning it is not trivial, but the lack of required privileges and user interaction lower the barrier. The EPSS score of less than 1% suggests that, currently, the likelihood of exploitation is very low, and the vulnerability is not in the CISA KEV catalog. Nevertheless, the availability of the issue and its remote impact warrant proactive remediation, as attackers could mount remote code execution by crafting specific HTTP requests.
OpenCVE Enrichment