Impact
A flaw in Oracle Labor Distribution allows an attacker with low privileges who can access the system over HTTP to perform unauthorized updates, inserts, or deletions of data. The vulnerability is rated a CVSS Base Score of 3.1, indicating an impact limited to integrity with no confidentiality or availability effects reported. The weakness permits an attacker to alter business data within the application without proper authorization, potentially leading to accounting inaccuracies or trust issues.
Affected Systems
The affected product is Oracle Corporation’s Oracle Labor Distribution component of Oracle E‑Business Suite, specifically the Internal Operations module. Versions 12.2.3 through 12.2.15 are impacted. Users running any of these releases should verify whether a later, secure version is available.
Risk and Exploitability
The CVSS score of 3.1 classifies the risk as low, and the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is HTTP network access to the Oracle Labor Distribution interface; an attacker would need only low privileges, such as an ordinary user account to exploit the flaw.
OpenCVE Enrichment