Impact
A vulnerability in the Oracle Labor Distribution Internal Operations component permits a low‑privileged attacker with network access via HTTP to fully compromise the application. The flaw results in a complete takeover, exposing confidentiality, integrity, and availability of the Oracle E‑Business Suite environment. The weakness combines information exposure, broken access control, and insufficient privilege checks, enabling the attacker to execute arbitrary operations under the application’s context.
Affected Systems
Oracle Labor Distribution in Oracle E‑Business Suite versions 12.2.3 through 12.2.15 is affected. All installations of these versions that expose the component to HTTP traffic are vulnerable and could be remotely compromised.
Risk and Exploitability
The CVSS 3.1 Base Score of 8.8 signifies high severity, while the EPSS score is less than 1%, indicating that real‑world exploitation probability is currently low. The vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the attack Vector is network based and requires only a low‑privileged user with HTTP access, the potential impact remains significant and organizations should treat this as a high‑risk finding. Based on the description, it is inferred that the attacker must possess network access via HTTP to the component.
OpenCVE Enrichment