Impact
The flaw resides in Oracle Work in Process’s Internal Operations component of Oracle E‑Business Suite. An attacker with low‑privileged access and HTTP network connectivity can exploit it to read all data that the process can see, and in some scenarios can also insert, update or delete data. The vulnerability requires that a user other than the attacker interact with the system, and it can affect additional Oracle products through a scope change. This leads to confidentiality and limited integrity compromises.
Affected Systems
Oracle Work in Process (Oracle E‑Business Suite component) versions 12.2.3 to 12.2.15 are affected.
Risk and Exploitability
The CVSS base score of 7.6 indicates high severity, while the EPSS score of less than 1% suggests a very low but non‑zero chance of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation is possible over HTTP with a low‑privilege attacker, but it calls for human interaction from a different user. If leveraged, the attacker could gain unauthorized read, and in some cases write access to critical data, which would jeopardize both confidentiality and integrity. Administrators should view this as a medium‑to‑high risk with low probability of exploitation.
OpenCVE Enrichment