Impact
The Oracle EDI Gateway flaw permits a low‑privileged attacker with network access via HTTP to read sensitive data that should be confidential. This is an unauthorized information disclosure vulnerability (CWE‑200) and results in a limited confidentiality loss; integrity and availability are unaffected.
Affected Systems
Oracle Corporation’s EDI Gateway product, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15. The product must be reachable over HTTP; if restricted to trusted networks the vulnerability is mitigated.
Risk and Exploitability
The CVSS 3.1 base score of 4.3 indicates a low severity attack that only impacts confidentiality. The EPSS score is below 1 % and the vulnerability is not listed in CISA KEV, suggesting a low likelihood of public exploitation. The attack path exploits the HTTP interface; a low‑privileged attacker can request data endpoints and retrieve a subset of data without authentication, consistent with CWE‑200.
OpenCVE Enrichment