Impact
A vulnerability in the Oracle Marketing Audience component allows an attacker with low privileges and network access via HTTP to read sensitive data. The flaw is an access‑control weakness (CWE‑284) that can be exploited without user interaction, resulting in a confidentiality impact. The vulnerability raises the system’s scope, so successful exploitation may also affect related Oracle E‑Business Suite products.
Affected Systems
Oracle Marketing, part of Oracle E‑Business Suite. The affected range covers versions 12.2.3 through 12.2.15. Any installation that exposes the Audience component to an HTTP network boundary is potentially vulnerable.
Risk and Exploitability
The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the CVSS 3.1 score of 7.7, with network access, low attack complexity, low required privileges, and a high confidentiality impact, points to a significant risk. Attackers only need basic network reach to Oracle Marketing, and the impact could extend to other products if the scope changes. The low privilege barrier and ease of remote exploitation underscore the potential threat.
OpenCVE Enrichment