Impact
A vulnerability in the Oracle Workflow Notification Mailer component allows an unauthenticated attacker who can reach the system via the SMTP interface to write unauthorized data to or delete data from Oracle Workflow, or to trigger a partial denial of service. The flaw is a result of missing authentication controls (CWE-306) and the ability to send oversized or malformed requests (CWE-400).
Affected Systems
Oracle Corporation’s Oracle Workflow product, part of Oracle E-Business Suite, is affected for all released versions from 12.2.3 through 12.2.15.
Risk and Exploitability
The vulnerability has a CVSS 3.1 score of 4.8, indicating low to moderate impact on integrity and availability. EPSS is below 1%, reflecting a very low probability of exploitation. It is not listed in the CISA KEV catalog. The likely attack vector is network-based SMTP access, as the description notes that the vulnerability is exploitable with network access via SMTP.
OpenCVE Enrichment