Impact
A low‑privileged Item Catalog component enables unauthorized access to critical data or all data accessible through the product hub. The vulnerability is described as easily exploitable and has scope changed (S:C), resulting in a high impact to confidentiality, with a CVSS 3.1 Base Score of 7.7.
Affected Systems
This issue affects Oracle Product Hub within Oracle E‑Business Suite, specifically the Item Catalog component. Affected versions include 12.2.3 through 12.2.15. The problem may also impact other integrated Oracle products that rely on Product Hub, extending the potential damage beyond the immediate product.
Risk and Exploitability
The CVSS score reflects a serious confidentiality risk, while the EPSS score of < 1% suggests a low likelihood that a public exploit is actively in use today. The vulnerability is not listed in CISA’s KEV catalog, indicating no known active exploitation in the wild as of the latest data. Nonetheless, the low‑privilege attacker requirement coupled with network‑level access via HTTP means that any user who can reach the hub could exploit the flaw. Organizations should treat this as a moderate‑to‑high risk, especially in environments where Product Hub interfaces with sensitive business data.
OpenCVE Enrichment