Impact
Improper access control (CWE‑284) in Oracle Product Workbench allows a remote attacker with low‑privileged HTTP access to create, delete, or modify any data accessible through the product. Successful exploitation can compromise data integrity and, in some scenarios, expose critical data, representing a significant confidentiality breach.
Affected Systems
Oracle Product Workbench, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, lack the fix for this remote HTTP privilege escalation.
Risk and Exploitability
The CVSS base score of 8.1 signals high severity, while the EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation. The vulnerability is triggered over the network via HTTP by a low‑privileged user, granting unauthorized data modification or full access to all data exposed by the Product Workbench. Although not listed in the CISA KEV catalog, its high impact and remote access vector warrant prompt action.
OpenCVE Enrichment