Impact
The vulnerability allows an unauthenticated attacker to gain unauthorized access to critical data via HTTP, resulting in a confidentiality breach. This improper authorization weakness permits data disclosure without compromising integrity or availability, with a CVSS v3.1 base score of 7.5 reflecting its high potential impact on confidentiality.
Affected Systems
Oracle Corporation’s Oracle Purchasing component of Oracle E‑Business Suite, specifically versions 12.2.3 through 12.2.15, are affected.
Risk and Exploitability
With an EPSS score of less than 1%, the probability of exploitation is considered very low. The CVSS base score of 7.5 indicates a high potential impact on confidentiality. The vulnerability is not listed in the CISA KEV catalog, so no known exploitation has been reported. The likely attack vector is an unauthenticated HTTP request from the network to the Oracle Purchasing application, which, if successful, grants the attacker access to all data the application can read.
OpenCVE Enrichment