Impact
A weak authorization control in Oracle Process Manufacturing Intelligence allows a low‑privileged attacker who can reach the system over Oracle Net to gain read access to confidential data. The privilege elevation is not limited to a single table; successful exploitation can expose all data accessible to the user, potentially compromising critical business information. The vulnerability does not provide code execution or denial‑of‑service, but the impact is a confidentiality breach at the application level.
Affected Systems
Oracle Process Manufacturing Intelligence versions 12.2.3 through 12.2.15 are affected. These versions are used within Oracle E‑Business Suite, specifically the Internal Operations component of the Process Manufacturing Intelligence module.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 indicates moderate severity with a focus on confidentiality. The EPSS score of less than 1% shows that, at present, exploit activity is expected to be very low. The vulnerability is listed outside the CISA KEV catalog. The attack vector is inferred to be network‑based via Oracle Net, requiring a low‑privileged account. Because the attacker needs network access and a valid account, exploitation is non‑automatic and likely limited to internal or attacker‑controlled network segments. Overall risk remains moderate, primarily due to potential data exposure rather than system compromise.
OpenCVE Enrichment