Impact
Oracle iSupplier Portal is vulnerable to a network-based attack that does not require authentication. An attacker who can reach the portal over HTTP can exploit this weakness to gain unauthorized access to critical or all data stored in the system, resulting in a high confidentiality impact. The vulnerability is classified as a high‑severity issue with a CVSS score of 7.5.
Affected Systems
The affected product is Oracle iSupplier Portal, part of Oracle E‑Business Suite. All versions from 12.2.3 through 12.2.15 are affected, regardless of patch level within that range.
Risk and Exploitability
The vulnerability is exploitable over standard HTTP without any prior credentials. An attacker only needs network access to the portal’s HTTP interface, making the attack vector trivial. With a CVSS score of 7.5 and an EPSS score of less than 1%, the risk remains significant; the vulnerability is not listed in the CISA KEV catalog, but the impact on confidentiality is severe. Because the flaw allows full data access, the potential damage from exploitation is considerable.
OpenCVE Enrichment