Impact
Oracle Application Object Library is vulnerable to an easily exploitable flaw that permits a low‑privileged attacker with network access via HTTP to read protected data. Supported versions 12.2.3 through 12.2.15 are affected. The vulnerability can lead to unauthorized disclosure of confidential information but does not affect integrity or availability.
Affected Systems
The affected product is Oracle Corporation's Oracle Application Object Library, which is a component of Oracle E‑Business Suite. Supported versions impacted range from 12.2.3 to 12.2.15. The flaw requires only low‑privileged access over HTTP; no privileged or elevated rights are necessary to succeed.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 reflects a moderate confidentiality impact. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Inferred from the description, the attack vector is network via HTTP, suggesting that remote attackers who can reach the exposed interface can leverage the flaw.
OpenCVE Enrichment