Impact
Oracle Sales Offline, part of Oracle E-Business Suite, has a vulnerability that can be exploited via HTTP requests. A low-privileged attacker with network access can gain unauthorized access to all data stored in the Sales Offline application, resulting in confidentiality loss of critical information.
Affected Systems
The affected product is Oracle Sales Offline, included in Oracle E-Business Suite, for supported versions ranging from 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS v3.1 base score of 7.7 indicates moderate-to-high severity. The EPSS score of less than 1% suggests a low probability of exploitation at this time, and the vulnerability is not listed in CISA KEV. Attackers can exploit the flaw from a network-connected low-privileged user via the HTTP interface; the vulnerability has a scope change, allowing compromise to extend beyond the Sales Offline component.
OpenCVE Enrichment