Impact
Vulnerability resides in the Product Diagnostic Tools component of Oracle Order Management for Oracle E‑Business Suite versions 12.2.3 through 12.2.15. An attacker with low privileges who can reach the system over HTTP can exploit the flaw, gaining unauthorized access to critical data or full access to all data that Oracle Order Management can expose. The known CVSS v3.1 Base Score of 6.5 reflects the impact on confidentiality, while integrity and availability remain unaffected.
Affected Systems
Oracle Corporation’s Oracle Order Management product, part of the Oracle E‑Business Suite, is affected. The vulnerability applies to all released sub‑versions in the 12.2.3–12.2.15 release line. Administrators should verify that their deployed instances fall within this range and are not patched.
Risk and Exploitability
CVSS 6.5 places the vulnerability in the moderate severity category. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The attack likely requires only network access to the HTTP interface and does not need elevated privileges beyond a low‑privileged user, making it relatively easy to exploit for an attacker who can reach the exposed endpoint.
OpenCVE Enrichment