Impact
A vulnerability in Oracle Compensation Workbench allows an attacker with low privileges and network access via HTTP to bypass proper access controls and obtain or alter sensitive compensation data. The weakness is an improper authorization flaw identified by CWE-284, which undermines the confidentiality and integrity of the application’s data. Exploitation can lead to both reading confidential records and performing unauthorized updates, inserts or deletes on the data stored within the system.
Affected Systems
The affected product is Oracle Compensation Workbench, part of Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are impacted; any build within this series should be considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS 3.1 Base Score of 7.1 reflects a high severity level, while the EPSS score of less than 1% indicates that exploitation is currently uncommon. The vulnerability is not listed in the CISA KEV catalog. Attackers are expected to exploit the HTTP interface with low privileges, leveraging the improper access control to gain unauthorized data access or modify it. The risk remains significant for organizations that expose Compensation Workbench over the network without stringent authentication and authorization controls.
OpenCVE Enrichment