Impact
This vulnerability enables a high‑privileged attacker with network access to the HTTP interface of Oracle Universal Work Queue to compromise the Work Provider Site Level Administration component. The impact is severe, as it can lead to full control over the application, exposing all confidential data stored in the work queue as well as the underlying database. The weakness is essentially an authorization flaw, allowing privilege escalation that affects all three security objectives: confidentiality, integrity, and availability.
Affected Systems
Oracle Universal Work Queue in Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are affected. Any deployment that exposes the Work Provider Site Level Administration over HTTP without proper access controls falls within the scope of this vulnerability.
Risk and Exploitability
The CVSS 3.1 base score of 6.6 indicates moderate severity; the vector AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H shows that a network attacker must already possess high privileges, likely administrative credentials, before exploitation. The EPSS score of less than 1% signals very low probability of real‑world exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The described attack path involves leveraging exposed HTTP services to bypass authorization checks, which implies that when high‑privilege credentials are available, the attacker can take over the whole system. Organizations should treat this as a high‑priority risk if the affected versions are in use.
OpenCVE Enrichment