Impact
Oracle Time and Labor in the Oracle E‑Business Suite contains a hard‑to‑exploit flaw in its internal operations component that allows an unauthenticated attacker to read a limited subset of data via HTTP. The vulnerability results in a confidentiality impact because sensitive information may be exposed without authentication or privilege escalation. The weakness is a classic information disclosure flaw, classified as CWE‑200.
Affected Systems
Oracle Time and Labor, part of the Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected. The flaw can be reached from external networks over standard HTTP, exposing the vulnerable interface to the internet.
Risk and Exploitability
The CVSS Base Score 3.7 indicates a low severity vulnerability. The EPSS score of less than 1 % and the absence of this vulnerability from the CISA KEV catalog suggest that exploitation is unlikely. However, the vulnerability does not require authentication and is reachable over HTTP, thus any Oracle Time and Labor instance exposed to the network may allow an attacker to read a subset of sensitive data.
OpenCVE Enrichment