Impact
The vulnerability in Oracle Sales Offline allows an unauthenticated attacker with network access via HTTP to gain unauthorized access to critical data. No authentication is required and the flaw results in a confidentiality compromise where sensitive information stored in the Sales Offline component can be disclosed. The flaw is rooted in improper access control, allowing users to request data without any checks for identity or privileges.
Affected Systems
Affected product is Oracle Sales Offline, part of Oracle E-Business Suite. Versions 12.2.3 through 12.2.15 are vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates a high severity. EPSS score less than 1% suggests low current exploitation probability, and the vulnerability is not listed in CISA KEV. An attacker with network connectivity to the HTTP interface can exploit the flaw. The flaw relies on no preconditions such as authentication or elevated privileges, making it easily exploitable for anyone who can reach the service.
OpenCVE Enrichment