Impact
Workflow in Oracle E‑Business Suite. A low‑privileged user who has local access can exploit a vulnerability that violates CWE‑284 (Improper Access Control) to alter, insert or delete data normally restricted to higher‑privileged workflow users. The attacker can also trigger a partial denial of service of the Oracle Workflow component. The impact is limited to integrity and availability for versions 12.2.3 through 12.2.15, with the flaw confined to the Workflow Notification Mailer component.
Affected Systems
The vulnerability affects Oracle Corporation’s Oracle Workflow component of Oracle E‑Business Suite, specifically the Workflow Notification Mailer. It impacts the releases from 12.2.3 through 12.2.15. Systems running these versions on infrastructure where a local low‑privileged account can log on are susceptible.
Risk and Exploitability
The CVSS base score is 3.6 and the EPSS score is less than 1 %; the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of widespread exploitation. Because the problem requires local access and low privileges, the attack surface is constrained. An attacker with a local account can log on to the host and interact with workflow data, potentially modifying entries or causing service interruptions. The risk remains comparatively low, but organizations with critical workflow processing should act promptly.
OpenCVE Enrichment