CVE-2019-12415 | Oracle Retail Predictive Application Server 15.0.3/16.0.3 RPAS Fusion Client xml external entity reference (WID-SEC-2025-0143)
A vulnerability marked as critical has been reported in Oracle Retail Predictive Application Server 15.0.3/16.0.3. The affected element is an unknown function of the component RPAS Fusion Client. This manipulation causes xml external entity reference.
This vulnerability is tracked as CVE-2019-12415. The attack is restricted to local execution. No exploit exists.
It is suggested to upgrade the affected component.