Impact
A vulnerability exists in the Internal Operations component of Oracle Time and Labor that allows an attacker with high privileges and network access over HTTP to compromise the system. Exploitation can lead to unauthorized access to critical data, full access to all Oracle Time and Labor accessible data, and the ability to insert, update or delete information. The weakness is classified as a high privileged attack with potential for integrity impacts.
Affected Systems
The affected product is Oracle Time and Labor, part of Oracle E-Business Suite, versions 12.2.3 through 12.2.15. No other vendors or product lines are listed as directly impacted.
Risk and Exploitability
The CVSS 3.1 base score of 6.6 indicates moderate severity, with confidentiality impact rated high and integrity impact low. The EPSS score of less than 1% suggests exploitation is unlikely but possible. The vulnerability is not listed in CISA KEV, yet the scope change indicates that attacks may also affect other Oracle E-Business Suite products. An attacker who has gained network access to the HTTP endpoint can exploit this flaw with high privileges, achieving unauthorized data manipulation.
OpenCVE Enrichment