Impact
A vulnerability in Oracle Work in Process, part of Oracle E-Business Suite, allows an attacker with low privileges and network access via HTTP to read sensitive data. The flaw does not enable code execution or disruption of service but does expose critical information, resulting in confidentiality loss. The CVSS 3.1 base score of 5.3 reflects this selective compromise, with the attack vector limited to network access and requiring high complexity to exploit.
Affected Systems
The issue affects Oracle Work in Process versions 12.2.3 through 12.2.15. Any deployment of this product that remains at or below version 12.2.15 and exposes the internal operations component over HTTP is subject to the risk.
Risk and Exploitability
The EPSS score is below 1 %, indicating a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the attacker needs only network connectivity to the affected HTTP interface and a low‑privilege account, making it relatively accessible in environments lacking strict access controls. Exfiltration of data could occur without detection if logging is insufficient.
OpenCVE Enrichment