CVE-2019-12415 | Oracle Retail Predictive Application Server 15.0.3 RPAS Fusion Client xml external entity reference (WID-SEC-2025-0143)
A vulnerability labeled as critical has been found in Oracle Retail Predictive Application Server 15.0.3. Impacted is an unknown function of the component RPAS Fusion Client. The manipulation results in xml external entity reference.
This vulnerability is identified as CVE-2019-12415. The attack is only possible with local access. There is not any exploit available.
The affected component should be upgraded.