Impact
This vulnerability stems from insecure handling of the file download component in Oracle Web Applications Desktop Integrator. An attacker with limited privileges who can reach the application over HTTPS may force the system to download or expose sensitive files, resulting in unauthorized access to critical data. The issue is explicitly described as a low‑privilege, network‑accessible flaw that bypasses normal access restrictions.
Affected Systems
a component of Oracle E‑Business Suite, is affected for supported releases from 12.2.3 through 12.2.15. These versions are distributed by Oracle Corporation and deployed in many enterprise environments.
Risk and Exploitability
The CVSS v3.1 base score of 7.7 indicates a high severity threat to confidentiality with a low attack complexity and low privilege requirement. Despite the high score, the EPSS value of less than 1 % suggests that practical exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network access via HTTPS, and the impact is concentrated on data confidentiality with potential scope expansion to other products through the compromised application.
OpenCVE Enrichment