Impact
The vulnerability is an improper access control flaw in the file download component of Oracle Web Applications Desktop Integrator. A low‑privileged attacker who can reach the application over HTTP can trigger download requests that bypass authentication checks, allowing them to read sensitive data or gain complete access to any data exposed through the component, which directly compromises confidentiality.
Affected Systems
Oracle Web Applications Desktop Integrator, versions 12.2.3 through 12.2.15 are affected. Any deployment of those releases that still contains the unpatched file download feature is at risk.
Risk and Exploitability
With a CVSS v3.1 base score of 6.5 the flaw is categorized as moderate. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker only needs network access to the HTTP interface and low privileges to exploit the weakness, making the attack vector relatively simple but still potentially impactful for confidentiality.
OpenCVE Enrichment