Impact
Low‑privileged users achieving network access through HTTPS can exploit an authorization flaw in Oracle Public Sector Financials (International), leading to unauthorized access to critical or all available data. The flaw can also change the attack scope, potentially affecting other Oracle products. Confidentiality is the primary concern, with no explicit integrity or availability impact described.
Affected Systems
Oracle Public Sector Financials (International) of Oracle E‑Business Suite, versions 12.2.6 through 12.2.15, is the affected product. The vulnerability is confined to this product but may impact other Oracle components due to a scope change.
Risk and Exploitability
The CVSS 3.1 base score of 7.7 reflects a high‑severity vulnerability that does not require user interaction and is easily exploitable by an attacker with low privileges. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Attackers would likely target the HTTPS interface of the application, leveraging the scope change to gain broader access. Given the ease of exploitation and the confidentiality impact, the risk to exposed systems remains significant until mitigated.
OpenCVE Enrichment