Impact
The defect resides in Oracle Property Manager's internal operations component. A local attacker possessing high privileges on the same host can exploit the mis‑configured access controls, allowing them to retrieve a restricted subset of data that is normally protected by the application. This flaw does not grant code execution or integrity compromise but exposes sensitive information to the attacker, representing a confidentiality breach.
Affected Systems
Oracle Property Manager versions from 12.2.3 through 12.2.15 on Oracle E‑Business Suite are impacted. The issue was identified in the internal operations module and can be exploited only by users who can log on to the host where the service runs.
Risk and Exploitability
The CVSS score of 1.9, combined with an EPSS score of less than 1 % and absence from the CISA KEV list, signals a low immediate risk. The attack requires local privileged access and high effort. Still, because the vulnerability permits reading protected data, organizations should verify application versions, apply available fixes, and restrict local privilege escalation where feasible.
OpenCVE Enrichment