Impact
The vulnerability is an improper access control flaw (CWE-284) in Oracle Report Manager. It allows a low-privileged attacker with network connectivity over HTTPS to gain unauthorized access to critical data and to all data that is normally protected by Report Manager. Successful exploitation can also induce a partial denial of service, reducing the availability of the application. The flaw does not appear to affect data integrity.
Affected Systems
Oracle Report Manager, part of Oracle E-Business Suite, is affected in supported releases 12.2.3 through 12.2.15. The vulnerability is present in the Internal Operations component and is relevant for deployments that expose the HTTPS interface to external or internal users with limited privileges.
Risk and Exploitability
The CVSS score of 7.1 places the issue in the high-severity range, while the EPSS score of less than 1% indicates a very low probability that the flaw will be exploited in the wild. The flaw is not currently listed in CISA’s KEV catalog. Exploitation requires network access to the HTTPS service and a non-privileged user account, making it relatively easy for an attacker who can reach the Report Manager endpoint to leverage the flaw. Because the damage includes both confidentiality loss and partial disruption, the overall risk remains significant despite the low EPSS score.
OpenCVE Enrichment