Impact
The vulnerability in Oracle One-to-One Fulfillment allows a low‑privileged attacker who can access the physical communication segment attached to the device's hardware to compromise the application. Successful exploitation can lead to a full takeover of Oracle One-to-One Fulfillment, affecting confidentiality, integrity, and availability. The issue roots from a weak privilege management flaw identified as CWE‑269.
Affected Systems
The product affected is Oracle One-to-One Fulfillment, part of Oracle E‑Business Suite. Versions from 12.2.3 through 12.2.15 inclusive are impacted.
Risk and Exploitability
The CVSS base score of 8.0 reflects severe impact. The EPSS score of less than 1% suggests exploitation is unlikely, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is the physical communication segment that requires local access and low privileges (inferred). If an attacker gains that access, the application could be taken over.
OpenCVE Enrichment