Impact
The Oracle Middleware Common Libraries and Tools product includes a Remote Diagnostic Agent component that is vulnerable. The flaw allows a low‑privileged attacker who has logged into the underlying infrastructure to compromise the agent, leading to a full takeover of the middleware which results in loss of confidentiality, integrity and availability for the affected system.
Affected Systems
The vulnerability affects Oracle Middleware Common Libraries and Tools versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. The Remote Diagnostic Agent component runs on the entry point for exploitation.
Risk and Exploitability
The CV 7.8 indicates high severity with complete confidentiality, integrity and availability impact. The EPSS score of less than 1% suggests a low probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to first log in with low‑privilege rights to the host, after which the compromised agent can be taken over. Because the attack vector is local, only hosts that can be accessed by an attacker are at risk, yet any compromised system can lead to a total middleware takeover.
OpenCVE Enrichment