Impact
Oracle Universal Work Queue is affected by a low‑privileged network vulnerability that permits an attacker with HTTP access to create, delete, or modify critical data. This flaw is a weakness in access control (CWE‑284) that exposes confidentiality and integrity of all accessible data without impacting availability. Successful exploitation allows unauthorized users to change or delete information that is integral to the organization’s operations.
Affected Systems
Oracle Corporation’s Oracle Universal Work Queue product, versions 12.2.3 through 12.2.15, is vulnerable. The issue is rooted in non‑media integration components and applies to any instance reachable over HTTP.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 reflects a high confidentiality and integrity impact with a network attack vector, low attack complexity, and low privilege requirement. The EPSS indicates a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA KEV, and the attack likely proceeds via direct HTTP requests to the affected service, allowing low‑privileged users to execute unauthorized operations.
OpenCVE Enrichment