Impact
This flaw exists in the Internal Operations component of Oracle Public Sector Financials, part of Oracle E‑Business Suite. It allows a low‑privileged attacker with network access over HTTP to read a small subset of data that the application exposes. The vulnerability leads to a confidentiality breach, giving attackers unauthorized access to sensitive business information.
Affected Systems
Oracle Public Sector Financials, within Oracle E‑Business Suite, is affected in releases 12.2.3 through 12.2.15. These are the only versions known to contain the flaw.
Risk and Exploitability
The CVSS base score of 3.1 indicates low severity, and the EPSS score of less than 1 % reflects a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to reach the system over HTTP and to have low‑privilege credentials, making successful attacks unlikely but still possible for adversaries who obtain legitimate network access.
OpenCVE Enrichment