Impact
The Oracle Applications Framework Personalization component allows a low‑privileged attacker with network access over HTTP to compromise the framework, effectively achieving full control over the application environment. The Base CVSS 3.1 score of 8.8 reflects a severe threat that would compromise confidentiality, integrity, and availability for any user or system relying on the framework.
Affected Systems
Oracle Corporation’s Applications Framework in Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are impacted. Users running these releases and exposing the framework over HTTP are at risk.
Risk and Exploitability
The high CVSS score indicates a serious vulnerability, but the EPSS probability is under 1 % and the issue is not listed in CISA KEV, suggesting limited active exploitation at present. Nevertheless, the attack vector is a simple HTTP request from a low‑privileged source, meaning no special credentials or privileged network access are required for an adversary to execute an attack that could lead to total takeover.
OpenCVE Enrichment