Impact
The vulnerability resides in the Documents component of Oracle One-to-One Fulfillment within Oracle E‑Business Suite. A low‑privileged attacker who can reach the application over HTTP can exploit this issue to gain unauthorized access to critical data and cause a partial denial of service. The flaw allows the attacker to read sensitive information and disrupt availability when accessed through a standard web interface, without requiring elevated user rights or interaction from the victim.
Affected Systems
Oracle Corporation’s Oracle One-to-One Fulfillment product is affected in versions 12.2.3 through 12.2.15. The advisory notes that the vulnerability may have a scope change, potentially impacting additional Oracle products that interact with the affected module.
Risk and Exploitability
The CVSS score of 7.1 reflects a high severity with substantial confidentiality impact and moderate availability impact. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be network‑based via HTTP to the Oracle One-to-One Fulfillment service; the attacker requires only low privileges on the network. Given the high confidentiality impact and the potential for service disruption, organizations should treat this as a priority for remediation.
OpenCVE Enrichment