Impact
The vulnerability is an unauthenticated remote access flaw that allows an attacker to interact with the Oracle SDP Number Portability component of Oracle E‑Business Suite over HTTP, potentially reading all data exposed by the service. The weakness originates from insufficient access‑control checks during HTTP interaction, enabling disclosure of confidential data without credentials. This can compromise the confidentiality of critical data within the application.
Affected Systems
Oracle SDP Number Portability, a component of Oracle E‑Business Suite, is affected. The vulnerable range includes supported releases from 12.2.3 through 12.2.15. All installations that have not applied the Oracle security patch for this issue remain at risk.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 signals a high‑severity exploitation scenario. The vulnerability is reachable over a network via HTTP, requires no authentication or user interaction, and would grant unauthorized access to all data exposed by the service. The EPSS score is less than 1%, and the vulnerability is not listed in CISA KEV, indicating a low probability of exploitation but still notable risk, with no known exploitation activity reported as of this analysis.
OpenCVE Enrichment