Impact
A flaw in the Command Line – RapidClone component of Oracle Applications Manager enables an attacker who is not authenticated to read critical data exposed can be triggered from any network host that can reach the HTTP endpoint, and it allows unrestricted read access, affecting confidentiality without impacting integrity or availability. The flaw is identified by a CVSS 3.1 Base Score of 7.5, reflecting a high potential for confidentiality compromise.
Affected Systems
Oracle Corporation’s Oracle Applications Manager, part of Oracle E‑Business Suite 12.2.3-12.2.15. These releases expose a command‑line interface that is reachable via HTTP.
Risk and Exploitability
The CVSS score indicates a serious threat to data confidentiality, while the EPSS score of less than 1% suggests that exploitation has not yet been seen widely, and the vulnerability is not listed in the CISA KEV catalog. The vulnerability is exploitable over the network, requiring no authentication or special privileges; any host with HTTP connectivity to the Application Manager can potentially obtain sensitive data.
OpenCVE Enrichment