Impact
A flaw in Oracle Contracts Integration permits an attacker who has only low privileges and network access through HTTP to send crafted requests that expose sensitive data. The vulnerability is an information‑disclosure weakness (CWE‑200) and can enable the attacker to view critical data that the component handles. No code execution or denial of service capabilities are granted by this issue.
Affected Systems
Oracle Contracts Integration, a part of Oracle E‑Business Suite, affected versions 12.2.3 through 12.2.15 are impacted by the disclosure flaw.
Risk and Exploitability
The CVSS 3.1 base score of 5.3 indicates moderate severity with a primary confidentiality impact. An EPSS score of less than 1% suggests a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers only require remote HTTP access on the Contracts Integration interface and can operate with low privilege credentials; no user interaction or elevated rights are needed. The risk is considered manageable but warrants prompt remediation to prevent potential data leakage.
OpenCVE Enrichment