Impact
Oracle Mobile Application Server is vulnerable to a flaw in the MWA Terminal Server component that allows an attacker who can reach the server over a TCP network connection to execute code without authentication. The weakness directly compromises confidentiality, integrity, and availability of the server application, effectively enabling an attacker to take full control of the Oracle Mobile Application Server. The vulnerability is identified as an Authentication Failure (CWE‑287) and an Authorization Failure (CWE‑306).
Affected Systems
Oracle Mobile Application Server, versions 12.2.3 through 12.2.15 of Oracle E‑Business Suite.
Risk and Exploitability
This critical flaw has a CVSS v3.1 Base Score of 9.8. The EPSS score of less than 1% suggests a low probability of exploitation at the time of this analysis, yet the required conditions are minimal—a network accessible TCP connection and no authentication. The vulnerability is not currently listed in the CISA KEV catalogue. An exploited instance would result in a complete takeover of the application server, providing full administrative rights to the attacker.
OpenCVE Enrichment