Impact
The vulnerability in the Personalization component of Oracle Applications Framework permits a low‑privileged attacker with network access via HTTP to compromise the framework, exposing confidentiality, integrity, and availability. This flaw is a privilege‑escalation vulnerability (CWE‑269).
Affected Systems
Oracle Applications Framework versions 12.2.9 through 12.2.15 are affected. Any system running these releases within an Oracle E‑Business Suite deployment is vulnerable, regardless of whether the framework is exposed externally or internally.
Risk and Exploitability
The CVSS vector shows a network attack with low complexity, low privilege, no user interaction and a base score of 8.8. Exploitation is highly feasible by sending crafted requests to the Personalization endpoint, granting full control of the framework and potentially enabling access to sensitive data across the application. Despite an EPSS of less than 1 %, the vulnerability poses a high risk and is not listed in the CISA KEV catalog.
OpenCVE Enrichment