Impact
A vulnerability in Oracle low‑privilege credentials and access to the physical communication segment that the product uses to interact with external hardware to compromise the application. Successful exploitation results in a takeover of the Oracle One-to-One Fulfillment instance and impacts confidentiality, integrity and availability. The vulnerability is rated as easily exploitable in the local environment, giving the attacker control over the target system.
Affected Systems
The affected vendor is Oracle Corporation and the product is Oracle One-to-One Fulfillment. Supported versions in the affected range span from 12.2.3 to 12.2.15 inclusive. No other vendors or product lines are listed as impacted.
Risk and Exploitability
The vulnerability carries a CVSS 3.1 base score of 8.0, indicating severe impact. The EPSS score is below 1 %, suggesting exploitation is unlikely but not impossible, and the issue is not currently listed in CISA’s KEV catalog. The likely attack vector is through a physical communication segment that an attacker can reach, which provides an avenue for local privilege escalation and takeover.
OpenCVE Enrichment