Impact
Oracle iSupport, part of Oracle E‑Business Suite, contains a flaw in its Internal Operations component that is easily exploitable by a low‑privileged attacker with network access over HTTP. The vulnerability permits the attacker to compromise the iSupport application, resulting in unauthorized reading of critical data. Because the weakness causes a scope change, the compromise may additionally impact other Oracle E‑Business Suite components that interact with iSupport, extending the potential damage beyond the localized service.
Affected Systems
Oracle iSupport versions from 12.2.3 through 12.2.15 are affected. No other vendors or products are mentioned; the scope change indicates that any Oracle components that rely on or communicate with iSupport could be indirectly impacted once iSupport is compromised.
Risk and Exploitability
The flaw carries a CVSS 3.1 base score of 7.7, reflecting a medium‑to‑high confidentiality impact. The EPSS score is below 1 %, indicating a very low but non‑zero likelihood of exploitation in the field. The vulnerability is not listed in CISA’s KEV catalog. Exploitation can be performed over the web without user interaction and requires only low privileges, but the scope‑changing nature can lead to a broader compromise.
OpenCVE Enrichment