Impact
Oracle Applications Manager includes a flaw in its Diagnostics Interfaces component. When a low‑privileged attacker accesses the HTTP interface, the vulnerability permits full compromise of the application, allowing the attacker to execute arbitrary code, exfiltrate data, and modify or delete resources. The impact covers confidentiality, integrity and availability, reflected in a CVSS 3.1 base score of 8.8.
Affected Systems
The affected product is Oracle Applications Manager, part of Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are impacted. The flaw resides in the Diagnostics Interfaces service exposed over HTTP.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, though the EPSS score is less than 1%, suggesting a low current exploitation likelihood. The vulnerability is not listed in CISA KEV. Attackers can exploit it remotely via HTTP with only low privileges, requiring no elevated permissions or prior authentication. Successful exploitation leads to complete takeover of the Oracle Applications Manager instance.
OpenCVE Enrichment