Impact
The flaw in Oracle iSupplier Portal, part of the Internal Operations component of Oracle E‑Business Suite, allows an unauthenticated attacker who can reach the system over HTTP to read a limited set of information that should otherwise be protected. This is a CWE‑200 information disclosure flaw. The vulnerability does not facilitate control, privilege escalation, or denial of service; it only permits read access to certain data.
Affected Systems
Vulnerable instances include Oracle Corporation's Oracle iSupplier Portal versions 12.2.3 through 12.2.15. Any deployment of this product within that range is exposed; newer releases are not listed as affected.
Risk and Exploitability
With a CVSS 3.1 base score of 3.7, the vulnerability carries low severity, reflecting modest confidentiality impact. The EPSS score is under 1%, indicating a very small exploitation probability at the moment of reporting, and it is not referenced in the CISA KEV catalog. The attack vector is inferred to require network connectivity to the HTTP interface of the portal, and the vulnerability can be triggered without authentication, making it accessible to any network‑present adversary.
OpenCVE Enrichment