Impact
A vulnerability in the Internal Operations component of Oracle Document Management and Collaboration allows an unauthenticated attacker with network access over HTTP to bypass authentication and fully compromise the application. This flaw results in complete loss of confidentiality, integrity, and availability, with the potential for arbitrary code execution and data exfiltration. The weakness is identified as an authentication bypass (CWE-287) combined with insecure configuration (CWE-306), reflected in a CVSS 3.1 base score of 9.8.
Affected Systems
The affected product is Oracle Corporation’s Oracle Document Management and Collaboration, part of Oracle E‑Business Suite. Version numbers 12.2.3 through 12.2.15 are listed as vulnerable.
Risk and Exploitability
An attacker only needs HTTP access to the vulnerable endpoint; no authentication or elevated privileges are required. The EPSS score indicates a very low probability of widespread exploitation, but the high CVSS score and absence from the CISA KEV list underscore a still significant risk. Successful exploitation allows an attacker to take over the entire instance, read or modify any data, and execute arbitrary code.
OpenCVE Enrichment