Impact
The flaw is in the Internal Operations component of Oracle In‑Memory Cost Management for Discrete Industries and allows an unauthenticated attacker who can reach the application over HTTP to bypass authentication checks. An attacker can exploit the weakness to read critical data or gain complete access to all data exposed by the product. This results in a significant confidentiality impact with no impact to integrity or availability.
Affected Systems
Oracle In‑Memory Cost Management for Discrete Industries, a component of Oracle E‑Business Suite, is affected. Versions 12.2.3 through 12.2.15 are reported to contain the vulnerability; no other Oracle products or versions are mentioned as impacted.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 reflects high confidentiality impact with an attack vector of network, low attack complexity, and no privileges required. The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because the flaw can be exploited without authentication over an exposed HTTP interface, organizations that allow network access to the affected appliance should treat this as a moderate‑to‑high risk and apply remediation promptly.
OpenCVE Enrichment