Impact
The vulnerability exists in the Internal Operations component of Oracle Workflow within Oracle E‑Business Suite. An unauthenticated attacker with network access through SMTP can send crafted traffic that causes the workflow engine to be fully compromised. Successful exploitation leads to a complete takeover of Oracle Workflow, giving the attacker full control over the application – enabling read, modify, delete and further lateral attacks. The weakness is a classic authentication bypass (CWE‑284) and results in confidentiality, integrity, and availability impacts.
Affected Systems
Oracle Workflow components of Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are affected. These specific releases expose the Internal Operations module and are the only ones identified as vulnerable, with no other product or version listed in the CNA data.
Risk and Exploitability
The CVSS v3.1 Base Score of 8.1 signals high severity. While exploitation requires high effort, the attack can be performed remotely via SMTP without credentials, making it achievable in the wild. The weakness corresponds to improper authentication (CWE‑284). An EPSS score of < 1 % indicates a currently low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog at present. Nonetheless, the potential impact warrants prompt patching.
OpenCVE Enrichment