Impact
A flaw exists in the Workflow Loader component of Oracle E-Business Suite that permits an attacker who has high privileges and can reach the system over HTTP to gain unauthorized access to critical data stored within Oracle Workflow. The vulnerability does not lead to denial of service or remote code execution but can expose all data that the workflow application can access. The weakness is classified as an improper authorization failure, mapping to CWE-284, and is reflected in a CVSS Base score of 4.9, highlighting a high confidentiality impact while integrity and availability remain unaffected.
Affected Systems
Oracle Corporation’s Oracle Workflow product in Oracle E‑Business Suite, specifically versions 12.2.3 through 12.2.15, is affected.
Risk and Exploitability
The CVSS severity indicates a moderate risk level, and the EPSS score of less than 1% suggests that exploitation is currently unlikely but not impossible. The vulnerability is not listed in CISA’s KEV catalog, meaning it has not yet been confirmed in publicly known exploits. The likely attack path requires an attacker with elevated (high) privileges and network access to the HTTP interface of the Workflow Loader. If these conditions are met, the attacker can read any data the workflow application can access.
OpenCVE Enrichment