Impact
The vulnerability permits a lower‑privileged user with Complex Maintenance, Repair and Overhaul component of Oracle E‑Business Suite. Successful exploitation can lead to a complete takeover, compromising confidentiality, integrity, and availability of the affected system. The weakness is a deficiency in access control that allows unauthorized commands to be executed remotely without user interaction.
Affected Systems
Oracle Corporation’s Complex Maintenance, Repair and Overhaul product within the Oracle E‑Business Suite, specifically the Internal Operations component. Versions 12.2.3 through 12.2.15 are affected, as noted by the Oracle security alert for this CVE.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 indicates high severity. The EPSS score of less than 1% suggests that the probability of exploitation in the wild is currently low, and the vulnerability is not listed in the CISA KEV catalog. However, the vulnerability can be triggered remotely over HTTPS by an attacker with low privileges and can result in full control of the application. Based on the description, it is inferred that allowing the attacker to submit specially crafted input that leads to remote code execution. As a result, this remains a serious threat.
OpenCVE Enrichment