Impact
The Oracle Supply Chain Trading Connector for Oracle E‑Business Suite suffers an easily exploitable flaw within the Collaboration History component. An attacker with a low level of privileges and network access through HTTP can exploit the bug to read sensitive data or gain full access to all data available in the Connector. The defect poses a high confidentiality impact, as detailed in the CVSS vector.
Affected Systems
All versions of Oracle Supply Chain Trading Connector from 12.2.3 to 12.2.15 are vulnerable. Affected deployments are those running Oracle E‑Business Suite with the Connector service exposed to the network.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity, with confidentiality compromised and no impact on integrity or availability. The EPSS score of < 1% indicates a very low probability of successful exploitation at the time of this analysis, suggesting that the vulnerability is unlikely to be actively targeted. Because the vulnerability is not listed in the CISA KEV catalog, no known active exploitation is reported. Attackers would likely send crafted HTTP requests to the Connector’s Collaboration History endpoint from a low‑privileged or unauthenticated context, granting unauthorized read access to critical data and enabling extraction of proprietary information.
OpenCVE Enrichment