Impact
A confidentiality flaw in Oracle Project Contracts, identified as CWE‑200, allows an attacker with low privileges and network access over HTTP to read a limited set of contract data that should otherwise be protected. While exploitation is difficult, a successful attack yields only a partial leak of sensitive information.
Affected Systems
Oracle Corporation’s Oracle Project Contracts component of Oracle E‑Business Suite is impacted, with vulnerable versions ranging from 12.2.3 through 12.2.15.
Risk and Exploitability
The vulnerability carries a CVSS base score of 3.1 and an EPSS score less than 1 %, indicating a very low likelihood of exploitation. It is not listed in the CISA KEV catalog. Attacks would need network reachability to the application via HTTP and an existing low‑privilege account, making it a low‑severity issue in most environments.
OpenCVE Enrichment