Impact
The Oracle Labor Distribution product in Oracle E‑Business Suite contains a flaw that permits a high‑privileged user who can log on locally to the host to create, delete, or modify data within the application. This results in a violation of data integrity, potentially allowing unauthorized tampering of critical records. The vulnerability does not affect confidentiality or availability.
Affected Systems
Oracle Labor Distribution component of Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are affected. These versions run on infrastructure where users have direct logon access.
Risk and Exploitability
The CVSS v3.1 base score of 4.1 suggests moderate severity. The EPSS score is below 1 % and the vulnerability is not listed in CISA KEV, indicating low likelihood of widespread exploitation. However, the flaw requires local high‑privilege access, so only environments where privileged users can log on to the server are at risk. No remote exploitation path is documented.
OpenCVE Enrichment