Impact
Vulnerability in Oracle XML Gateway enables a low-privileged attacker who can reach the service over HTTP to obtain unauthorized access to critical data or full data exposed by the gateway, and to trigger a partial denial of service. The flaw is exploitable with minimal effort, requiring only network connectivity to the gateway endpoint and no special credentials. The CVSS vector indicates a high confidentiality impact and a low availability impact with a base score of 7.1.
Affected Systems
Oracle XML Gateway in Oracle E-Business Suite versions 12.2.3 through 12.2.15 is affected. The vulnerability exists specifically in the Install component of the product. Systems running any of these versions with the gateway exposed to the network are at risk.
Risk and Exploitability
The attack vector is via the HTTP interface of the XML Gateway, so an attacker only needs to reach the gateway’s network port. While the EPSS score is < 1 %, indicating a low current exploitation probability, the CVSS 7.1 score and the high confidentiality impact mean that the vulnerability is still significant. The flaw is not listed in the CISA KEV catalog, but organizations should consider it a moderate-to-high risk until mitigated. If an effective patch or configuration change is applied, the risk is eliminated.
OpenCVE Enrichment