Impact
The Oracle Product Hub within Oracle E‑Business Suite allows a low‑privileged attacker who can reach the hub over HTTP to read critical data or gain full access to all Oracle Product Hub data. The CVSS 3.1 Base Score of 7.7 reflects a high confidentiality impact with no impact on integrity or availability. The vulnerability arises in the Item Catalog component and permits unauthorized data access when the attacker does not possess proper authentication or authorization.
Affected Systems
Oracle Product Hub, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15. The vulnerability originates in this product but the scope change in the CVE description indicates that successful exploitation could also impact additional products or systems that interact with the Product Hub.
Risk and Exploitability
The vulnerability is network‑based and requires only HTTP access over port 80/443, as explicitly stated in the CVE description. The attacker can be any compromised user with low privileges who has network connectivity to the host. Authentication is not required, so the attacker can read critical data or gain complete access to the Product Hub. The likely attack vector is through HTTP requests to the Item Catalog endpoint; this is inferred from the description. The CVSS base score of 7.7 indicates high risk to confidentiality, while the EPSS score of < 1% shows a low overall probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, and the scope change noted in the description suggests that successful exploitation could also impact additional products that interact with the Product Hub.
OpenCVE Enrichment