Impact
This vulnerability enables an attacker who is not authenticated to connect over HTTP to the Internal Operations component of Oracle Warehouse Management. The flaw bypasses normal authentication checks, allowing unauthorized read of critical data. The CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N indicates that the impact is limited to confidentiality while integrity and availability are not directly affected.
Affected Systems
Affected vendors and products include Oracle Corporation’s Oracle Warehouse Management, which is part of Oracle E‑Business Suite. The CVE specifically targets supported versions from 12.2.3 through 12.2.15. This affects all deployments of those versions unless patched or otherwise secured.
Risk and Exploitability
The CVSS base score of 7.5 classifies this as a high‑severity vulnerability with significant risks if left unpatched. EPSS score is < 1%, indicating a very low exploitation probability, but the lack of authentication requirements and simple network access via HTTP suggest that attackers could readily target it. The vulnerability is not currently listed in the CISA KEV catalog, but the undisclosed exploitation potential warrants a proactive response.
OpenCVE Enrichment