Impact
The Oracle HCM Configuration Workbench vulnerability allows an attacker with high‑privileged credentials and network access to the HTTP interface to take full control of the workbench. Successful exploitation can compromise confidentiality, integrity, and availability for all processes that rely on the configuration workbench, effectively enabling a takeover of the entire Oracle E‑Business Suite Rapid Implementation component.
Affected Systems
Oracle HCM Configuration Workbench, part of Oracle E‑Business Suite's Rapid Implementation component, is affected for versions 12.2.3 through 12.2.15. Users of these versions are exposed to an HTTP service that can be reached from the network.
Risk and Exploitability
The CVSS 3.1 base score of 7.2 places the vulnerability in the high severity range. However, the EPSS score of less than 1% suggests a very low current exploitation probability, and the flaw is not listed in the CISA KEV catalog. The attack requires high‑privileged credentials and network access to the HTTP endpoint; once those prerequisites are met, the attacker can achieve a full takeover of the configuration workbench.
OpenCVE Enrichment