Impact
The Oracle Universal Work Queue flaw allows an unauthenticated attacker with HTTP network access to influence critical data by creating, deleting, or modifying entries. Because the weakness relies on improper authentication and access control, it can lead to significant confidentiality and integrity loss for all data managed by the work queue. Successful exploitation does not grant full administrative rights, but it enables an attacker to corrupt or erase vital business processes and data sets.
Affected Systems
Oracle Universal Work Queue, part of the Oracle E‑Business Suite, is affected for supported releases 12.2.3 through 12.2.15. Any installation of these versions that exposes the UWQ server over the network is vulnerable.
Risk and Exploitability
With a CVSS 3.1 base score of 8.1, the vulnerability is classified as high severity. The EPSS score of less than 1% indicates low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Attacks would require an attacker to reach the UWQ server over HTTP and enlist a different human actor to trigger the malicious action, thereby limiting automated exploitation. Despite the low propagation risk, the potential for data compromise makes it a priority to contain the exposure.
OpenCVE Enrichment