Impact
The vulnerability resides in the Personalization component of Oracle Applications Framework, a part of Oracle E‑Business Suite. It allows a low‑privileged user with network connectivity through HTTP to perform actions that compromise the entire framework. The impact is a full takeover that results in loss of confidentiality, integrity, and availability, as the CVSS vector shows high impact on all three dimensions.
Affected Systems
Oracle E‑Business Suite product Oracle Applications Framework versions 12.2.9 through 12.2.15 are affected. The issue is specific to the Personalization component of this framework.
Risk and Exploitability
The CVSS base score of 8.8 indicates high‑severity vulnerability that can be exploited remotely with low effort. The EPSS score of less than 1% suggests that, while the technical probability of exploitation is low, the existence of network‑based access and low privilege requirements means that an attacker could still exploit it in practice. The vulnerability is not yet listed in CISA’s KEV catalog. Attackers likely need only casual HTTP access to the affected Oracle Applications Framework instance, though the exploitation path and specific payload details are not disclosed in the available data.
OpenCVE Enrichment