Impact
The vulnerability allows an attacker with low privileges who can reach the system over HTTP to compromise the Oracle HCM Configuration Workbench. Successful exploitation leads to unauthorized access to critical data, potentially giving the attacker full read access to all data exposed by the Workbench. The weakness manifests as a confidentiality impact, with a CVSS 3.1 Base Score of 6.5 and a vector indicating that the attack can be performed over the network without user interaction. The vulnerability is classified under CWE-200 (Information Exposure).
Affected Systems
Affected vendors and products include Oracle Corporation’s Oracle HCM Configuration Workbench, a component of Oracle E‑Business Suite. The vulnerability applies to supported versions ranging from 12.2.3 through 12.2.15. Earlier or later releases are not known to be affected.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests that the vulnerability is expected to be rarely exploited, and it is not currently listed in CISA’s KEV catalog. However, because the attack requires only network access via HTTP and low‑privileged credentials, the practical risk remains significant for environments that expose the Workbench over a network. An attacker could leverage the vulnerability to read sensitive data that the Workbench makes available, thereby compromising confidentiality.
OpenCVE Enrichment