Impact
The vulnerability resides in the internal operations component of Oracle U.S. Federal Financials and allows unauthenticated attackers with HTTPS network access to bypass missing authentication, granting read‑only access to all confidential data available through the application. The flaw involves improper authentication (CWE‑284) and a confidentiality issue (CWE‑200), and does not affect integrity or availability.
Affected Systems
Oracle U.S. Federal Financials, part of Oracle E‑Business Suite, from version 12.2.3 through 12.2.15, is affected; the internal operations component is exposed via HTTPS. Although the primary target is this product, the vulnerability’s scope may extend to other Oracle products linked or accessed through the same service.
Risk and Exploitability
The CVSS 3.1 base score of 6.8 indicates medium severity, while the EPSS score of less than 1% indicates a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers with network access to the affected HTTPS interface can attempt to use the identified authentication bypass; if successful, the attacker would obtain read‑only access to all data the application can return, effectively compromising confidential information.
OpenCVE Enrichment