Impact
Oracle Trading Community, part of Oracle E‑Business Suite, contains a flaw in its Third Party Data Integration component that allows an unauthenticated attacker with network access to HTTP to obtain unauthorized access to critical data or, in the worst case, all data exposed through the product. The vulnerability is easily exploitable and grants the attacker full control over confidentiality of data, with no impact on integrity or availability. The flaw is an authentication bypass combined with improper authorization.
Affected Systems
Affected versions are Oracle Trading Community 12.2.3 through 12.2.15. The vendor is Oracle Corporation. No platforms or operating system details are specified beyond the product identifier.
Risk and Exploitability
The CVSS v3.1 score is 8.6, indicating high severity. The vector indicates a network‑based, low‑complexity attack requiring no privileges, no user interaction, and a changed scope, meaning exploitation may affect other components. The EPSS score is 0.00398 (<1 %) and the vulnerability is not listed in the CISA KEV catalog, indicating a very low exploitation probability but high impact, which warrants close attention. An attacker can trigger the flaw by sending a crafted HTTP request to the affected component, potentially leading to unauthorized data disclosure.
OpenCVE Enrichment