Impact
The vulnerability in Oracle Sales of Oracle E‑Business Suite allows a low‑privileged attacker who can reach the service over HTTP to obtain unauthorized read access to sensitive data stored within the Internal Operations component. The flaw bypasses normal access controls, meaning that once exploited an attacker may retrieve critical data or, in the worst case, all data that the Sales application exposes.
Affected Systems
Oracle Corporation’s Oracle Sales product, part of the Oracle E‑Business Suite, is affected. The vulnerability exists in versions 12.2.3 through 12.2.15 and applies to the Internal Operations component.
Risk and Exploitability
The flaw carries a CVSS 3.1 base score of 7.7, indicating high severity for confidentiality. The EPSS score is below 1 %, implying that while the vulnerability is technically exploitable, the current exploitation likelihood in the wild is low. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers would need network access to the Oracle Sales HTTP interface and use low‑privilege credentials; upon successful exploitation, they could read all data that the application makes available to that user, exposing confidential information and potentially compromising the entire data set.
OpenCVE Enrichment