Impact
A flaw in the Internal Operations component of Oracle Time and Labor allows an attacker who already has high privileges and network access via HTTP to compromise the application. The weakness is a failure of access control, as indicated by the CWE identifiers 269 and 284, meaning the system does not properly limit what authorized users can do. Exploitation can leak sensitive business data, give the attacker a view of all data the application can reach, and enable insert, update or delete actions on that data.
Affected Systems
The affected product is Oracle Time and Labor, part of Oracle E-Business Suite. Versions 12.2.3 through 12.2.15 are vulnerable. A scope change in the CVE notes indicates that a successful attack could also impact other Oracle E-Business Suite products that interact with Time and Labor.
Risk and Exploitability
The CVSS 3.1 base score of 6.6 shows moderate severity with high confidentiality impact and low integrity impact, and no availability impact. The EPSS score of less than 1 % suggests exploitation is unlikely but possible. The vulnerability is not listed in CISA KEV. An attacker would need to reach the HTTP endpoint from within the network and possess high‑privilege credentials; from there, the flaw can be abused to read or alter any data the application is allowed to see or modify.
OpenCVE Enrichment