Impact
The vulnerability is an authentication bypass in the Oracle Applications Framework’s Personalization component. An attacker with network access can send specially crafted SOAP requests to the framework without providing any credentials, because the component fails to enforce proper authentication. Successful exploitation allows the attacker to execute arbitrary operations with the privileges of the framework, potentially leading to complete takeover of the application.
Affected Systems
Oracle Corporation’s Oracle Applications Framework, part of Oracle E‑Business Suite, is affected in versions 12.2.3 through 12.2.15. These include the Personalization service, and any deployment of the framework within the specified E‑Business Suite releases.
Risk and Exploitability
The vulnerability carries a CVSS 3.1 base score of 9.8, reflecting critical confidentiality, integrity, and availability impacts. The EPSS score is below 1 %, indicating a currently low likelihood of exploitation, yet the severity warrants immediate action. The risk remains high because the attack vector is network‑based via unauthenticated SOAP calls, enabling full compromise of the framework without requiring prior access. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment