Impact
The vulnerability in the Oracle Assets component of Oracle E-Business Suite permits a low‑privileged attacker with network access over HTTP to obtain unauthorized access to critical or all data stored within Oracle Assets. It carries a confidentiality impact as reflected by the CVSS score of 6.5 and the vector indicating a high confidentiality impact without integrity or availability consequences.
Affected Systems
Oracle Corporation’s Oracle Assets product, part of the Oracle E-Business Suite's Internal Operations component, is affected. Versions 12.2.3 through 12.2.15 are vulnerable. Any installation of these releases that is reachable via HTTP is susceptible.
Risk and Exploitability
The risk is moderate with a CVSS base score of 6.5. The EPSS score of less than 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely using network access to the HTTP interface, requiring only low privileges and no user interaction. The vulnerability can be exploited by an attacker who can reach the application.
OpenCVE Enrichment