Impact
The vulnerability resides in the Internal Operations component of Oracle iSupplier Portal versions 12.2.3 to 12.2.15. It is a data‑disclosure flaw (CWE‑200) that permits a low‑privileged attacker with network access via HTTP to read restricted data from the portal, compromising confidentiality while leaving integrity and availability untouched. The CVSS base score of 3.1 reflects this modest impact, with a low confidentiality effect only.
Affected Systems
Affected systems include Oracle Corporation’s iSupplier Portal product as part of Oracle E‑Business Suite, specifically the 12.2.3 to 12.2.15 release range. No other vendors or products are listed in the advisory.
Risk and Exploitability
The CVSS base score of 3.1 indicates low severity, with a low confidentiality impact and no impact on integrity or availability. The EPSS score of less than 1% points to a very low probability of exploitation. Attackers would need network access to the portal’s HTTP interface; based on the description, it is inferred that simple HTTP requests can retrieve restricted data. The high attack complexity and low privilege requirement make this a shallow threat for environments running the affected versions. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment