Impact
The Oracle Labor Distribution product (Oracle E‑Business Suite component) has a flaw that permits a low‑privileged user over HTTP to cause a partial denial of service. The weakness stems from improper handling of malformed or excessive requests, leading to resource exhaustion. As a result, only availability is impacted, with no compromise of confidentiality or integrity.
Affected Systems
Oracle Labor Distribution versions 12.2.3 through 12.2.15 are affected. This includes all supported releases within that range as documented in the Oracle CPU advisory for July 2026.
Risk and Exploitability
The CVSS base score of 3.1 indicates a low severity impact, while the EPSS score of less than 1% indicates a very unlikely exploit scenario. The vulnerability is not listed in the CISA KEV catalog. Remote attack via HTTP is required, and only a low‑privilege account is necessary on the target network.
OpenCVE Enrichment