Impact
The Oracle XML Gateway vulnerability is a remotely exploitable flaw that permits a low‑privileged attacker with network access through HTTP to gain unauthorized access to critical data or to take full control of the gateway’s accessible data. Successful exploitation can also trigger a partial denial of service, reducing the gateway’s availability. The weakness is reflected in a CVSS 3.1 Base score of 7.1, indicating high confidentiality impact and moderate availability impact.
Affected Systems
Affected are Oracle XML Gateway components of Oracle E‑Business Suite in versions 12.2.3 through 12.2.15, as specified by the vendor.
Risk and Exploitability
This is a network‑based threat; the attacker only needs HTTP connectivity to the gateway and no elevated privileges. The EPSS score is less than 1 %, suggesting that exploitation attempts are currently uncommon, and it is not listed in CISA’s KEV catalog. Nonetheless, the confirmed ability to exfiltrate sensitive data or disrupt service warrants immediate attention. The CVSS score of 7.1 quantifies the risk of insecure access and potential service degradation if the vulnerability is left unpatched.
OpenCVE Enrichment