Impact
The Oracle Work in Process component is vulnerable to a local privilege issue that allows an authenticated user with low privileges to read a limited set of data exposed by the product and to trigger a partial denial of service. The weakness is consistent with CWE‑200 information disclosure and CWE‑404 missing error handling. The exploit does not grant system‑wide control but can manifest a modest confidentiality breach and an availability disruption within the application.
Affected Systems
Oracle Work in Process, part of Oracle E‑Business Suite’s Internal Operations component, is affected in version ranges 12.2.3 through 12.2.15 released by Oracle Corporation. The product runs on infrastructure where users have local access, and the vulnerability is confined to that installation.
Risk and Exploitability
The CVSS v3.1 base score of 3.6 reflects modest confidentiality and availability impact, while the EPSS score of less than 1 % indicates a very low likelihood of exploitation in the wild. Exploitability requires local or low‑privileged logon to the host running Oracle Work in Process, so it is not remotely exploitable. The attack enables only read access to a subset of data and a limited service interruption, and it does not provide elevation to higher privileges or full system compromise. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment