Impact
A vulnerability in the Oracle Marketing component allows a low‑privileged attacker with network access via HTTP to compromise the system, gaining unauthorized read access to all Oracle Marketing data. The weakness is an access‑control flaw (CWE‑284) that escalates privileges to read data that should remain restricted. The CVSS 3.1 score of 7.7 reflects low attack complexity, low required privileges, no user interaction, but a high confidentiality impact and potential to affect more than one product if the scope changes.
Affected Systems
Oracle Marketing, part of Oracle E‑Business Suite, vendors include Oracle Corporation. The affected range is versions 12.2.3 through 12.2.15. Any versions that exposes the Audience component to an HTTP network boundary is potentially vulnerable.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. However, given the remote network reach over HTTP and the low privilege barrier, the risk to confidential data remains significant. Attackers only need basic network access to Oracle Marketing, and the impact can extend to other products if the scope shifts. The CVSS vector shows network access, low complexity, and low privilege, underscoring the ease of exploitation once reach is achieved.
OpenCVE Enrichment