Impact
The Oracle Mobile Application Server contains a flaw in its MWA Terminal Server component that can be triggered by unauthenticated HTTP requests. Successful exploitation requires the presence of a human user other than the attacker to interact with the system, such as initiating a session or responding to a prompt, after which the attacker can cause a forced crash or complete denial of service and gain unauthorized ability to update or delete data exposed by the server. The weakness is described by CWE-400, indicating improper resource management that can be exploited to perform denial of service or unauthorized data modifications.
Affected Systems
Oracle Mobile Application Server versions 12.2.3 through 12.2.15, distributed with Oracle E‑Business Suite, are impacted. These versions remain in active production use in many organizations.
Risk and Exploitability
The CVSS 3.1 Base Score of 8.2 indicates high severity, reflecting low attack complexity, no required privileges, and the need for user interaction from a third party. The EPSS score of less than 1% points to a very low probability of exploitation in the wild, and the flaw is not listed in CISA’s KEV catalog. Nevertheless, because the flaw can be triggered via unauthenticated HTTP requests and can result in critical availability and integrity losses, exposed servers that are not patched remain at high risk.
OpenCVE Enrichment