Impact
Oracle Data Integrator’s Patchset Assistant contains a vulnerability that allows a low‑privileged user who has logged into the underlying infrastructure to read restricted data that should be confidential (CWE‑200). The problem is localized to the data integrator component and results in a confidentiality impact only, as reflected in the CVSS vector AV:L/AC:L/PR:L/UI:N/S:U/C:L.
Affected Systems
The affected products are Oracle Data Integrator versions 12.2.1.4.0 and 14.1.2.0.0. These releases are part of Oracle Fusion Middleware and are named Oracle Data Integrator.
Risk and Exploitability
This vulnerability includes information disclosure (CWE‑200), the CVSS base score of 3.3 indicates low severity, and the EPSS score of less than 1% shows a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need local access to the infrastructure where Oracle Data Integrator runs; no remote exploitation capability is specified. Successful exploitation could let an attacker read a subset of data that it normally could not access.
OpenCVE Enrichment