Impact
The vulnerability is an information disclosure flaw (CWE-200) in Oracle U.S. Federal Financials. An attacker with low system privilege who can reach the application via HTTP can obtain unauthorized read access to a subset of data that the application exposes. It affects confidentiality only; integrity and availability are unaffected, and the CVSS 3.1 Base Score of 4.3 reflects the moderate risk level.
Affected Systems
The flaw exists in the Oracle U.S. Federal Financials component of Oracle E‑Business Suite, specifically the Internal Operations module. Affected supported versions range from 12.2.3 through 12.2.15. The vulnerability is reachable over the network through HTTP requests to the application.
Risk and Exploitability
At the time of analysis the CVSS score is 4.3, indicating a moderate severity. The EPSS score is below 1 %, suggesting that active exploitation is uncommon. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw from the network without elevated privileges, using a simple HTTP request to trigger the data disclosure. The risk is therefore moderate but with a low chance of exploitation in the wild.
OpenCVE Enrichment