Impact
The flaw resides in the Core component of Oracle Application Object Library, part of Oracle E‑Business Suite. A local user who can log into the host with low privileges can compromise the library and gain unauthorized access to the data it stores or processes. The attack does not require user interaction, and the impact is a full confidentiality breach of all library data. The vulnerability is an improper authorization flaw that can also extend its reach to other Oracle products sharing the same environment, due to a scope‑changing condition.
Affected Systems
Oracle Corporation’s Application Object Library in Oracle E‑Business Suite is affected for versions 12.2.3 through 12.2.15, specifically the Core component.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates a moderate severity risk. The EPSS score of less than 1% shows that the likelihood of real‑world exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access to the infrastructure where the library runs and a low‑privileged user account; once exploited, confidentiality is fully compromised, and the scope change may affect other Oracle products sharing the environment.
OpenCVE Enrichment