Impact
Oracle Labor Distribution, part of Oracle E‑Business Suite, contains an access control weakness that is easily exploitable by a low‑privileged attacker who can reach the system over HTTP. The flaw allows the attacker to update, insert, delete, and read data that should be restricted, leading to confidentiality and integrity violations without affecting availability. The vulnerability is attributed to improper authorization checks (CWE‑284).
Affected Systems
Oracle Corporation’s Oracle Labor Distribution product, versions 12.2.3 through 12.2.15, is impacted. These versions are part of the internal operations component of the E‑Business Suite.
Risk and Exploitability
The CVSS 3.1 score of 5.4 indicates a moderate risk to confidentiality and integrity. The EPSS score of less than 1% suggests a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Likely attack paths involve an HTTP endpoint that can be accessed by low‑privileged users; the attacker does not require administrative privileges or network isolation to succeed, but must have network connectivity to the target host.
OpenCVE Enrichment