Impact
Oracle Marketing in Oracle E‑Business Suite has a vulnerability that enables a low‑privileged attacker with network access via HTTP to compromise the system. Successful exploitation can lead to unauthorized access to critical data or full exposure of all Oracle Marketing accessible data, resulting in a confidentiality breach. The flaw is considered easily exploitable and may cause significant impact beyond the Marketing component.
Affected Systems
The vulnerability affects Oracle Marketing versions 12.2.3 through 12.2.15. These releases are part of the Oracle E‑Business Suite and are used by organizations that rely on Marketing services.
Risk and Exploitability
The vulnerability carries a CVSS 3.1 Base Score of 7.7 with an AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N vector, indicating high potential for confidentiality impact when accessed over the network. EPSS data is not available and the flaw is not listed in CISA’s KEV catalog, suggesting it has not yet been widely exploited publicly. The likely attack vector requires network connectivity over HTTP and a low‑privileged user account, making it feasible for adversaries with limited access.
OpenCVE Enrichment