Impact
Oracle Learning Management's Import And Export component contains an information disclosure flaw that allows a low‑privileged network user to retrieve restricted data over HTTP. The vulnerability does not require authentication beyond local network access, and if exploited an attacker could read critical data stored in the platform. The flaw stems from incorrect access controls within the export feature, and is classified as CWE‑200.
Affected Systems
Affected versions are Oracle Learning Management 12.2.3 through 12.2.15, which are part of the Oracle E‑Business Suite. The vulnerability is documented in Oracle's CPU July 2026 advisory but is not listed in the CISA KEV catalog. Any system running one of the specified releases is exposed.
Risk and Exploitability
The CVSS Base score of 6.5 indicates a moderate severity for confidentiality. The EPSS score is below 1%, suggesting that exploitation in the wild is currently unlikely, yet the flaw is easily exploitable with network access and low privilege. Based on the description, the likely attack vector is local network via HTTP; an attacker could potentially scan for the import/export endpoint, gain unauthorized data reading, and exfiltrate sensitive information. No public exploit has been reported, but the vulnerability remains a credible threat for organizations with exposed Learning Management instances.
OpenCVE Enrichment