Impact
A flaw in the Oracle Proposals component of Oracle E‑Business Suite permits a low‑privileged user with network connectivity to the HTTP service to gain unauthorized access to confidential proposal data. The vulnerability, which is easy to exploit, can lead to reading or obtaining all data available through Oracle Proposals, and the vendor indicates a potential scope change that could affect other products in the same environment. The weakness is classified under CWE‑284, reflecting the absence or misimplementation of proper authorization controls.
Affected Systems
Oracle Proposals versions 12.2.3 through 12.2.15 are affected. All installations of these releases that expose the HTTP interface to the network are vulnerable, and the scope change suggests that other Oracle E‑Business Suite components might also be impacted if they share the same authentication mechanisms.
Risk and Exploitability
The base CVSS score of 7.7 indicates a significant impact on confidentiality, while the EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, implying a low current exploitation probability. Attacking the flaw requires only network access over HTTP and a low‑privilege account; no user interaction is needed. If successfully leveraged, the attacker could obtain full access to the data exposed by Oracle Proposals, compromising data privacy and potentially exposing sensitive business information.
OpenCVE Enrichment