Impact
The vulnerability resides in the Search Bean component of Oracle Applications Framework, part of Oracle E‑Business Suite. It allows an attacker with low privileges who can reach the application over HTTP to compromise the framework. Successful exploitation can lead to unauthorized access to critical data and, in some cases, the ability to insert, update, or delete data available through the framework. The CVSS 3.1 score of 7.1 reflects significant confidentiality damage and moderate integrity impact.
Affected Systems
Oracle Applications Framework in Oracle E‑Business Suite versions 12.2.3 through 12.2.15 is affected. The flaw impacts the Search Bean (including Advanced) component that handles search functionality exposed over HTTP.
Risk and Exploitability
The risk is moderate to high; the CVSS score indicates serious confidentiality loss. The EPSS score of less than 1 % suggests that, at the time of analysis, real‑world exploitation is unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. The attack vector appears to be network via HTTP with low conduct privilege, meaning that any user who can reach the exposed component may exploit the flaw as long as they can send crafted HTTP requests to it.
OpenCVE Enrichment