Impact
Oracle Application Object Library is vulnerable to an easily exploitable flaw that permits an attacker with low privileges and network access via HTTP to read protected data. The weakness leads to unauthorized disclosure of confidential information but does not affect integrity or availability.
Affected Systems
The affected product is Oracle Corporation's Oracle Application Object Library, which is a component of Oracle E‑Business Suite. Supported versions impacted range from 12.2.3 to 12.2.15. The flaw requires only low‑privileged access over HTTP; no privileged or elevated rights are necessary to succeed.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 reflects a moderate confidentiality impact. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Inferred from the description, the attack vector is network via HTTP, suggesting that remote attackers who can reach the exposed interface can leverage the flaw.
OpenCVE Enrichment