Impact
The flaw lies in Oracle Capacity, part of Oracle E‑Business Suite, where a remote low‑privileged attacker can abuse HTTP requests to bypass authentication controls and read data that the attacker is not authorized to see. This results in a high confidentiality impact, as the attacker may access all data exposed by Oracle Capacity. The weakness corresponds to improper access control, allowing unauthorized reading of protected information.
Affected Systems
Oracle Capacity, a component of Oracle E‑Business Suite, with affected releases 12.2.3 through 12.2.15. The impact may also extend to other Oracle products that rely on Capacity’s internal operations due to a scope change.
Risk and Exploitability
The vulnerability carries a CVSS 3.1 base score of 7.7, indicating a high risk level. Its EPSS score is under 1%, suggesting a very low current exploitation probability, and it is not listed in CISA’s KEV catalog. Nevertheless, an attacker only requires low privilege and network access via HTTP, no user interaction, and can immediately compromise confidential data. The scope change noted in the description indicates that successful exploitation could affect additional Oracle products, raising the overall threat.
OpenCVE Enrichment