Impact
A publicly accessible HTTP endpoint in Oracle Application Object Library makes the system vulnerable to unauthenticated attacks that can leak sensitive data. An attacker can read critical information stored within the library without needing credentials, potentially exposing personal, financial, or strategic data. The vulnerability does not allow code execution or denial of service, but the loss of confidentiality can severely impact the organization’s compliance and trust.
Affected Systems
Oracle Corporation’s Oracle Application Object Library component of E‑Business Suite is affected. Versions 12.2.3 through 12.2.15 are listed as vulnerable. No other vendors or product variants are indicated, and the vulnerability is specific to the Core product within the suite.
Risk and Exploitability
The CVSS 3.1 base score is 7.5, reflecting a high severity of confidentiality impact. The EPSS score is less than 1%, indicating a low exploitation probability in the current landscape, and the issue is not listed in the CISA KEV catalog. The vulnerability is exploitable over the network via HTTP in an unauthenticated session; the likely attack path involves a remote client issuing specially crafted requests to the exposed endpoint. As no authentication is required, an attacker with network access can exploit this flaw whenever the affected library is reachable.
OpenCVE Enrichment