Impact
The flaw occurs in the Security component of Oracle Enterprise Command Center Framework. It stems from improper enforcement of access controls over HTTP interfaces, allowing a low‑privileged user who can reach the endpoint to read data that the framework is meant to protect. The scope change noted in the advisory indicates that integrations with other Oracle products that rely on the same framework might also be exposed to the same data‑exposure risk.
Affected Systems
Oracle Corporation’s Enterprise Command Center Framework version 16 is affected. The vulnerability is limited to the Security component and no other products or versions are explicitly listed by the CNA. However, the scope change suggests that other components or products that embed or interact with the framework could be impacted as well.
Risk and Exploitability
The CVSS 3.1 base score of 7.7 classifies this as a high‑severity vulnerability. The EPSS score of less than 1 % indicates that exploitation is not widely observed at this time, but the potential for data exposure remains significant. The attack requires only a network‑level presence via HTTP and low privileges, making it relatively easy for an adversary to reach the target. Although it is not yet in the CISA KEV catalog, the combination of high confidentiality impact and scope expansion warrants immediate attention.
OpenCVE Enrichment