Impact
This vulnerability exists in the Internal Operations component of Oracle Price Protection, part of Oracle E‑Business Suite. It is an information disclosure flaw (CWE-200) that allows a low‑privileged attacker with network access over HTTP to read critical data exposed by the service. Successful exploitation would enable the attacker to access all data available through Price Protection, resulting in a confidentiality breach without impacting integrity or availability.
Affected Systems
Oracle Price Protection versions from 12.2.3 through 12.2.15 are affected. Administrators should confirm whether those releases are in use and review their current system configuration.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 reflects medium overall severity, driven by a high confidentiality impact (C:H). The EPSS score is below 1%, indicating that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalogue. Exploitation requires only network access to the HTTP endpoint and does not need elevated privileges, making it reachable by low‑privileged users on the same network segment.
OpenCVE Enrichment