Impact
A vulnerability in Oracle Mobile Application Server, specifically the MWA Terminal Server component, allows an unauthenticated attacker with network access over TCP to compromise the server. Successful exploitation can lead to a full takeover of the application server, impacting confidentiality, integrity, and availability. The weakness demonstrates improper access control and potential information exposure, as reflected in the associated CWEs.
Affected Systems
The affected systems are Oracle Mobile Application Server products from Oracle Corporation, with supported versions from 12.2.3 through 12.2.15.
Risk and Exploitability
With a CVSS v3.1 base score of 8.1, the vulnerability is considered high severity. However, the EPSS score of less than 1% indicates a low probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Attackers only need unauthenticated network connectivity on TCP to leverage the flaw, so restricting or monitoring this access remains an important protective measure.
OpenCVE Enrichment