Impact
The vulnerability in Oracle Financials Common Modules allows an attacker with only low system privileges and network access over HTTP to read critical data that should be protected. The flaw does not provide code execution or integrity manipulation; it results purely in confidentiality compromise as reflected in the CVSS vector, which lists a high confidentiality impact and no impact on integrity or availability.
Affected Systems
Oracle Corporation’s Oracle Financials Common Modules, versions 12.2.3 through 12.2.15, are affected. Any instance of these modules exposed to the network via HTTP is vulnerable, and components of Oracle E‑Business Suite that rely on these Common Components could also be implicitly exposed.
Risk and Exploitability
The CVSS base score of 7.7 classifies the vulnerability as high severity. The EPSS score is not available, and the flaw is not currently listed in the CISA KEV catalog. The attack vector is inferred to be remote over the network: a low‑privileged user can send crafted HTTP requests to the Common Components interface and, due to insufficient access control, retrieve confidential data. Because the scope is marked changed, exploitation may affect resources that the attacker does not normally have access to, amplifying the risk.
OpenCVE Enrichment