Impact
The vulnerability is a privilege escalation flaw that can be triggered over an HTTP interface. A remote attacker who possesses high‑level authentication credentials can exploit the flaw to elevate privileges within the Oracle Document Management and Collaboration component. The flaw allows the adversary to gain full control of the application, thereby exposing confidential data, allowing modification of content, and disrupting availability. The weakness is identified as CWE‑269 (Improper Privilege Management), which directly relates to the attacker’s ability to bypass access controls.
Affected Systems
Oracle Document Management and Collaboration in Oracle E‑Business Suite, version range 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, while the EPSS score of less than 1% suggests a very low likelihood that this vulnerability is being actively exploited. The vulnerability is not listed in the CISA KEV catalog, so there are no known widespread exploitation incidents. Exploitation requires HTTP access to the vulnerable endpoint and high‑privileged credentials; once those preconditions are met, the attacker can proceed with the privilege escalation without additional steps.
OpenCVE Enrichment