Impact
A flaw in Oracle Work in Process, part of Oracle E‑Business Suite, allows a high‑privileged attacker who has logged onto the same infrastructure to read a subset of data that should normally be protected. The vulnerability does not give code execution or denial of service; it simply bypasses normal authorization controls, leading to a confidentiality compromise consistent with CWE‑200, Information Exposure. The CVSS 3.1 score of 1.9 and vector AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N indicate a low overall impact limited to confidentiality.
Affected Systems
Oracle Work in Process running in Oracle E‑Business Suite versions 12.2.3 through 12.2.15 is affected. No other Oracle products or versions are listed as impacted by this CVE.
Risk and Exploitability
The attack vector is internal and local; the attacker must hold a high‑privilege account on the infrastructure where the product executes. The EPSS score of less than 1 % indicates a very low probability of exploitation in the wild, and the CVSS score of 1.9 reflects a minimal overall risk. The vulnerability is not recorded in the CISA KEV catalog. Organizations that allow privileged local users or lack strict role‑based access controls should assess the exposure and apply mitigations promptly.
OpenCVE Enrichment