Impact
A difficult to exploit flaw in Oracle Application Object Library allows a high‑privilege attacker with network access over HTTP to compromise the library, potentially enabling full takeover. The vulnerability is classified with CVSS Base Score 8.0 and affects confidentiality, integrity, and availability. Attackers could further impact other E‑Business Suite components because the vulnerability’s scope is changeable.
Affected Systems
The affected product is Oracle Application Object Library in Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, within the Core component.
Risk and Exploitability
The CVSS score of 8.0 indicates high severity, but the EPSS score is less than 1% and the issue is not in the CISA KEV catalog, implying low current exploitation prevalence. Exploitation requires a high‑privilege account with network access to the HTTP interface, making it realistic in environments where such privileges exist. Because the flaw can affect additional products, the overall impact is potentially broader than the library alone.
OpenCVE Enrichment