Impact
Oracle Public Sector Financials version 12.2.3 through 12.2.15 contains an access‑control bypass in the Internal Operations component that allows a low‑privileged network attacker to access sensitive financial data. The flaw enables unauthorized data retrieval without proper authentication, potentially exposing confidential records. The weakness is classified as CWE‑284, reflecting a permission‑or‑authorization failure.
Affected Systems
The affected product is Oracle Public Sector Financials from Oracle Corporation, specifically versions 12.2.3 to 12.2.15. These versions run the Internal Operations component that is vulnerable to the described access‑control bypass.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates a moderate severity, with a focus on confidentiality impact. The EPSS score of less than 1% suggests that exploitation is unlikely at present, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires the attacker to send specially crafted HTTP requests to the exposed Internal Operations endpoint, and the attacker only needs low‑level network privileges to exploit the flaw.
OpenCVE Enrichment