Impact
The vulnerability arises from improper access control and authentication in the Audience component of Oracle Marketing. An unauthenticated attacker who can reach the application over HTTP can retrieve sensitive marketing data without providing credentials, leading to disclosure of confidential customer information. The flaw is classified as an authentication bypass and a lack of adequate access control (CWE-284).
Affected Systems
Oracle Marketing, part of Oracle E-Business Suite, versions 12.2.3 through 12.2.15, is affected. The issue exists in the Audience component that exposes customer and campaign data.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high‑severity vulnerability that impacts confidentiality. The EPSS score is in the (0%,1%) interval, indicating a very low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Nevertheless, because the vulnerability can be triggered simply by sending HTTP requests without authentication, it can be exploited remotely by any adversary with network access to the Marketing web services.
OpenCVE Enrichment