Impact
A flaw in Oracle Workflow’s Notification Mailer component allows an attacker with high privileged local access to the system where Oracle Workflow runs to trigger a hang or crash, effectively causing a denial of service. The same privilege can also be used to update, insert, delete, or read data that belongs to the component, resulting in unauthorized data access. These impacts are reflected in the CVSS 3.1 base score of 5.2, which indicates low confidentiality and integrity damage but high availability loss.
Affected Systems
The vulnerability affects the Oracle Workflow product that is part of Oracle E‑Business Suite. All supported releases from version 12.2.3 through 12.2.15 contain the vulnerable component and are therefore subject to this issue.
Risk and Exploitability
The CVSS score indicates moderate severity, and the EPSS score is below 1%. The exploit requires the attacker to already have local high‑privileged access and is described as difficult to exploit. Consequently, the likelihood of widespread attacks is low, but the risk remains for systems where privileged users or compromised local accounts have access to Oracle Workflow.
OpenCVE Enrichment