Impact
The Oracle Workflow product contains a flaw in its Notification Mailer component that allows an attacker with low privileges and network access via HTTP to modify, insert, or delete data that is normally protected, read restricted data, and create a partial denial of service. This weakness aligns with improper access control and missing authorization, enabling compromise of confidentiality, integrity, and availability.
Affected Systems
Oracle Corporation’s Oracle Workflow component of Oracle E‑Business Suite, specifically versions 12.2.3 through 12.2.15, are affected by this vulnerability.
Risk and Exploitability
The CVSS 3.1 base score of 6.3 indicates moderate severity while the EPSS score of less than 1% suggests a very low probability of exploitation at this time. It is not listed in CISA’s KEV catalog. The likely attack vector is via network HTTP access, as the description states that low privileged attackers with such access can exploit the flaw. Successful exploitation would permit unauthorized data modification, read access, and a limited denial of service for the Oracle Workflow service.
OpenCVE Enrichment