Impact
The vulnerability in Oracle Sales permits a low privileged attacker with network connectivity over HTTP to gain unauthorized access to sensitive data stored within Oracle Sales. This flaw propagates beyond a single component, potentially affecting other related Oracle E‑Business Suite products, thereby increasing the overall data exposure risk. The weakness exposes confidential information and could lead to full data compromise for all users with access to Oracle Sales.
Affected Systems
Affected by Oracle Corporation’s Oracle Sales product in the Oracle E‑Business Suite, specifically the Internal Operations component. The vulnerability exists in versions 12.2.3 through 12.2.15, inclusive.
Risk and Exploitability
The flaw has a CVSS 3.1 base score of 7.7, indicating a high severity. The EPSS score is below 1%, suggesting that, while the vulnerability is properly exploitable, the current likelihood of real‑world exploitation is low. The vulnerability is not listed in CISA’s KEV catalog, further supporting the low exploitation probability. The likely attack vector is a low privileged user who can reach the Oracle Sales HTTP interface, allowing them to submit crafted requests that bypass normal access controls. Successful exploitation leads to unauthorized reading of critical data, raising significant confidentiality concerns.
OpenCVE Enrichment