Impact
This vulnerability arises from improper access control in the Outcome-Result component of Oracle Customer Interaction History. With low privilege, an attacker who can reach the application over HTTP can read protected data. The flaw allows a reader to disclose confidential customer interaction records, representing a high confidentiality impact and no impact on integrity or availability.
Affected Systems
Oracle Customer Interaction History in Oracle E-Business Suite versions 12.2.3 through 12.2.15 is affected. The issue is confined to the Outcome-Result component, but the scope flag indicates that successfully exploiting the weakness could affect additional Oracle E-Business Suite products that access or rely on Customer Interaction History data.
Risk and Exploitability
The CVSS 3.1 base score of 7.7 classifies this as a high severity vulnerability. The EPSS score of < 1% shows a low probability of exploitation at the current time, and the issue is not listed in the CISA KEV catalog. An attacker requires network access and basic HTTP knowledge; no elevated privileges or local access are needed. Successful exploitation would enable the attacker to retrieve all customer interaction history data indexed by the application.
OpenCVE Enrichment