Impact
An unauthenticated attacker with access to the physical communication segment attached to the hardware running Oracle Mobile Application Server can exploit a difficulty‑to‑exploit vulnerability in the MWA Terminal Server component. The weakness involves improper privilege escalation (CWE-269). Successful exploitation gives the attacker control over the entire Oracle Mobile Application Server. The vulnerability is classified as a high severity problem with a CVSS 3.1 score of 7.5, indicating significant impact for those who can reach the affected environment.
Affected Systems
Oracle Mobile Application Server from Oracle E‑Business Suite is affected. Versions from 12.2.3 through 12.2.15 are vulnerable. The vulnerability is confined to the MWA Terminal Server component and applies to deployments that use the specified hardware communication interface.
Risk and Exploitability
The CVSS score of 7.5 reflects the potential for full server compromise, but the exploit vector is physical local access (AV:A) and requires an unauthenticated attacker to be physically near the device. The EPSS score a low probability of exploitation in the wild, and the issue is not listed in CISA’s KEV. Unrestricted physical access to the server or weak perimeter controls are at higher risk of a compromise. Removing or isolating the communication interface and promptly applying vendor patches will mitigate the threat.
OpenCVE Enrichment