Impact
The vulnerability enables a low‑privileged attacker who can reach the Oracle Compensation Workbench over HTTP to bypass the application’s intended access controls. This allows unauthorized reading of critical data (high confidentiality impact) and modification operations such as insert, update, or delete (moderate integrity impact) on tables accessible through the workbench. The weakness is rooted in insufficient authorization checks.
Affected Systems
Oracle Compensation Workbench from Oracle Corporation is affected. The flaw applies to all supported versions between 12.2.3 and 12.2.15 inclusive, covering the Compensation Workbench component of Oracle E‑Business Suite.
Risk and Exploitability
The CVSS 3.1 Base Score of 7.1 indicates a high risk to confidentiality, with a low to medium likelihood of exploitation (EPSS <1%) and no listing in CISA’s KEV catalog. The exploit can be carried out remotely via the HTTP interface with only low privilege. Successful exploitation grants unauthorized access to and modification of the work data but does not extend to full system compromise.
OpenCVE Enrichment