Impact
The flaw is an information disclosure vulnerability (CWE‑200) that allows a low‑privileged attacker with network access to the Oracle Inventory Management HTTP interface to retrieve sensitive inventory data. Successful exploitation results in unauthorized read access to all data exposed by the service, without impacting integrity or availability. The CVE indicates a scope change, suggesting that the effect may extend to other Oracle products beyond Inventory Management.
Affected Systems
Oracle Inventory Management, part of Oracle E‑Business Suite, is affected for versions 12.2.3 through 12.2.15. The CVE notes a scope change suggesting that exploitation may also impact other Oracle products beyond Inventory Management, expanding the potential reach of the flaw.
Risk and Exploitability
The CVSS 3.1 base score of 7.7 denotes a high‑severity confidentiality risk. The EPSS score of less than 1% indicates that it is currently unlikely to be actively exploited in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the exploit requires only low privileges and network access via HTTP, making it remotely actionable for any user who can reach the Inventory Management process. The scope alteration also raises the potential to compromise additional Oracle applications.
OpenCVE Enrichment