Impact
A flaw in Oracle Work in Process, part of Oracle E‑Business Suite, enables an attacker with network access via HTTP to take full control of the application. The vulnerability lacks authentication checks and can be exploited to compromise confidentiality, integrity, and availability of the affected instance due to the CVSS 3.1 score of 9.8.
Affected Systems
The Oracle Work in Process product of Oracle E‑Business Suite – supported versions 12.2.3 through 12.2.15 – is affected. The issue resides in the Internal Operations component of the product.
Risk and Exploitability
Because the attack only requires network connectivity over HTTP and no valid credentials, the risk is high. The EPSS score of less than 1 percent suggests that active exploitation is currently rare, and the vulnerability is not yet listed in the CISA KEV catalog, but the severity remains critical. An unauthenticated attacker could execute arbitrary code or manipulate the application to achieve takeover of the entire Oracle Work in Process instance.
OpenCVE Enrichment