Impact
The Oracle Mobile Application Server product contains a flaw in the MWA Terminal Server component that allows an unauthenticated attacker with network access via TCP to bypass the authentication mechanism. A successful exploitation lets the attacker read any critical data exposed by the server and gain full access to all data the server can serve, while also being able to trigger a partial denial‑of‑service condition. The flaw carries a CVSS v3.1 base score of 8.2, indicating high confidentiality impact and moderate availability impact.
Affected Systems
Oracle Mobile Application Server, part of Oracle E‑Business Suite, is affected for all supported releases from version 12.2.3 through 12.2.15. No other vendors or product versions are listed as impacted by this vulnerability.
Risk and Exploitability
The vulnerability’s CVSS score of 8.2 signals high severity, but the EPSS score of less than 1 % indicates a very low probability of exploitation at this time, and the issue is not listed in the CISA KEV catalog. Nonetheless, any remote actor who can reach the server over TCP, as it requires no prior authentication and can be performed by an unauthenticated connection. The impact would be complete compromise of the server’s data and a partial denial‑of‑service.
OpenCVE Enrichment