Impact
A flaw in the G‑Invoicing module of Oracle Purchasing allows a low‑privilege user with network access over HTTP to bypass normal access controls and read data that should be restricted. The vulnerability can result in exposure of all purchasing‑related information accessible through the application, directly compromising the confidentiality of the system’s data.
Affected Systems
Oracle Purchasing versions 12.2.10 through 12.2.15 are affected. Attacks may extend beyond the Purchasing module because the vulnerability changes the scope of protected resources, potentially impacting other components of the Oracle E‑Business Suite that share data with Purchasing.
Risk and Exploitability
The CVSS v3.1 base score of 7.7 reflects a high‑severity confidentiality impact. The EPSS score is less than 1%, indicating a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Attackers only need low privilege and the ability to reach the application over HTTP, which makes the attack vector feasible for remote actors with minimal access. If exploited, the attacker could gain unauthorized read access to all data the application can provide, and the scope change raises the danger of affecting other Oracle products that share the same data store.
OpenCVE Enrichment