Impact
A vulnerability exists in the Personalization component of Oracle E‑Business Suite’s Applications Framework that enables a high privileged attacker to compromise the framework over HTTP. Successful exploitation results in full takeover of the framework, allowing the attacker to modify or delete data and potentially disrupt business processes. The CVSS vector indicates that confidentiality, integrity, and availability are all fully impacted.
Affected Systems
Oracle Applications Framework versions 12.2.3 through 12.2.15 are affected. Attackers must have network access to the HTTP interface of the framework and must possess high level privileges within the environment to exploit this weakness.
Risk and Exploitability
The CVSS base score of 7.2 indicates high severity. The EPSS score of <1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in CISA’s KEV catalog. However, because the attack vector is network‑based over HTTP, an attacker with earlier network foothold can trigger the flaw; the required high privilege level suggests that the flaw is best exploited from within or through trusted accounts. The CVSS base score and the lack of a public exploit do not reduce the need for prompt remediation.
OpenCVE Enrichment