Impact
An easily exploitable flaw in Oracle Marketing Encyclopedia System allows a low‑privileged attacker with network access via HTTP to compromise the system and obtain unauthorized access to critical data, potentially gaining full access to all data the application exposes. The vulnerability is not limited to this product; if exploited, it may impact additional products in the Oracle E‑Business Suite due to a scope change. The attack requires no user interaction and does not affect integrity or availability, but it does endanger confidentiality.
Affected Systems
Oracle Marketing Encyclopedia System, part of Oracle E‑Business Suite, Internal Operations component. Supported affected versions are 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS v3.1 base score of 7.7 indicates a high‑severity vulnerability driven by confidentiality impact. The EPSS score is currently unavailable, and the issue is not listed in the CISA KEV catalog. The attack vector is network‑based using HTTP; a low‑privileged attacker can exploit the flaw without authentication or privileged access, making it readily exploitable in environments where the application is exposed to the network.
OpenCVE Enrichment