Impact
A flaw in Oracle Demand Signal Repository allows an attacker who can reach the application over HTTP and has only low privileged access to execute arbitrary code on the server. The vulnerability can lead to a complete takeover of the repository, exposing, modifying, or deleting data and disrupting service. The weakness is reflected by CWE-269.
Affected Systems
Oracle Corporation’s Demand Signal Repository component of Oracle E‑Business Suite, specifically versions 12.2.3 through 12.2.15, is vulnerable to this exploit.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 indicates a severe security risk. The EPSS score of less than 1% indicates that the current likelihood of observed exploitation is low, and the vulnerability is not listed in CISA’s KEV catalog. The vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) shows that an attacker needs only network connectivity to an exposed HTTP endpoint and no special credentials to exploit this flaw, making the attack path straightforward for candidates with network access.
OpenCVE Enrichment