Impact
This vulnerability in Oracle Time and Labor’s Internal Operations component allows an attacker with low privileges to perform unauthorized creation, deletion or modification of data. Successful exploitation results in loss of data integrity and can trigger a partial denial of service, impacting business operations. Based on the description, it is inferred that the weakness is improper access control, enabling the attacker to bypass the intended authorization checks.
Affected Systems
Oracle Time and Labor, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15. The issue affects the Internal Operations module and can be reached via the standard HTTP interface.
Risk and Exploitability
The CVSS 3.1 base score of 7.1 reflects moderate to high impact on integrity and availability. The EPSS score of less than 1% shows a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers only need low‑privilege access and network connectivity to HTTP to exploit the flaw, making it a network‑based vulnerability that can be leveraged from remote hosts.
OpenCVE Enrichment