Impact
The vulnerability permits a high‑privileged attacker with local logon to the infrastructure where Oracle EDI Gateway runs to read a subset of data normally protected by the application. This is an information exposure weakness classified as CWE‑200. Successful exploitation results in a confidentiality impact while leaving integrity and availability unaffected.
Affected Systems
Oracle EDI Gateway, part of Oracle E‑Business Suite, supports versions 12.2.3 through 12.2.15; the issue resides in the Internal Operations module of the product.
Risk and Exploitability
The CVSS 3.1 base score of 1.9 reflects a low‑severity confidentiality effect. The EPSS score is reported as less than 1 %, indicating a very low probability of exploitation in real‑world environments, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local (AV:L) and requires high privileged access (PR:H). Exploitation is deemed difficult, but in environments where a local high‑privileged user is present, the read‑only attack described above can occur, so the risk, while low, warrants remediation through patching or other mitigation measures.
OpenCVE Enrichment