Impact
A vulnerability exists in the Oracle Depot Repair product of Oracle E‑Business Suite that allows a low‑privileged network user with Internet‑HTTP access to compromise the depot repair service. Successful exploitation results in a full takeover of the service, affecting confidentiality, integrity, and availability. The weakness enables remote code execution and privilege escalation to the account running the service.
Affected Systems
Oracle Corporation’s Oracle Depot Repair component of Oracle E‑Business Suite, intended for Internal Operations, is affected. Systems running versions 12.2.10 through 12.2.15 are at risk and should be reviewed for the presence of the fix.
Risk and Exploitability
The CVSS 3.1 score of 8.8 indicates high severity, but the EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low likelihood of widespread exploitation. Attackers would need only standard HTTP access to the target system and can attain low‑privilege execution as a starting point before taking full control of the service. The vulnerability is exploitable over the network and can be triggered by a remote user with modest privileges.
OpenCVE Enrichment