Impact
A flaw in the Oracle EDI Gateway component enables a low‑privileged attacker with network access over HTTP to read a subset of data that should be restricted. The vulnerability is classified as a confidentiality compromise, mapped to CWE‑200, highlighting insufficient protection of information.
Affected Systems
The affected product is Oracle EDI Gateway, part of Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are impacted. These versions are provided by Oracle Corporation.
Risk and Exploitability
The CVSS 3.1 base score of 4.3 indicates low‑to‑moderate severity, focusing on confidentiality. The EPSS score is less than 1%, showing a low likelihood of widespread exploitation; the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is network traffic over HTTP, requiring only low‑privileged or unauthenticated access to the network segment hosting the gateway. The exploitation path does not require elevated privileges or complex prerequisites, making it achievable by remote attackers who can reach the service.
OpenCVE Enrichment