Impact
The flaw exists in the Workflow Notification Mailer component of Oracle E‑Business Suite, allowing an unauthenticated attacker that can reach the system over HTTP to perform updates, inserts, or deletions of Oracle Workflow data, read restricted records, and trigger a partial denial of service. The weakness is a classic example of an improper access control flaw (CWE‑284) that compromises the confidentiality, integrity, and availability of the application.
Affected Systems
Affected systems are Oracle Workflow, specifically the Workflow Notification Mailer sub‑component of the Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are impacted; any deployment that exposes this component to the internet or an untrusted network is at risk.
Risk and Exploitability
The CVSS v3.1 base score of 7.3 indicates high severity, while the EPSS score of less than 1% shows a low but non‑zero likelihood of exploitation. Because the vulnerability requires only HTTP access and no prior authentication, exposed installations can be compromised quickly. Although the vulnerability is not listed in the CISA KEV catalog, the potential for unauthorized data manipulation and service disruption warrants prompt attention.
OpenCVE Enrichment