Impact
The Oracle Document Management and Collaboration product contains an easily exploitable flaw that allows a low‑privileged attacker with network access via HTTP to compromise the system and ultimately take over the application. The flaw can expose confidentiality, integrity, and availability of all data managed by the application. The weakness is consistent with improper authorization, enabling an attacker to act beyond intended privileges.
Affected Systems
Affected is Oracle Corporation’s Document Management and Collaboration component of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15. The product is widely deployed in enterprise environments.
Risk and Exploitability
The CVSS base score of 8.8 indicates high severity, while the EPSS score of less than 1% suggests that exploit attempts are currently uncommon. The flaw requires only low‑privileged network access and does not require user interaction from the network alone. Because the vulnerability is not listed in the CISA KEV catalog, it has not yet been confirmed as widely exploited but should be treated as a serious risk. The likely attack vector is remote over the network to the HTTP interface.
OpenCVE Enrichment