Impact
The vulnerability resides in the Install component of Oracle XML Gateway, part of Oracle E‑Business Suite, and permits an attacker with low‑privileged access and network connectivity over HTTP to bypass normal controls. Successful exploitation allows reading any data that the gateway can reach and can trigger a partial denial of service. The weakness involves insufficient validation and safeguarding of resources during request processing.
Affected Systems
Oracle XML Gateway in Oracle E‑Business Suite versions 12.2.3 through 12.2.15, deployed as the Install component within the suite.
Risk and Exploitability
The CVSS Base Score of 7.1 indicates moderate‑to‑high severity, while the EPSS score of less than 1% suggests an extremely low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires only low‑privilege credentials and network access over HTTP to the gateway; no additional prerequisites or privileged escalation steps are necessary.
OpenCVE Enrichment