Impact
The vulnerability is a weakness in the Spreadsheet Loading component of Oracle HCM Configuration Workbench that allows an unauthenticated attacker with network access via HTTP to modify, insert, or delete data, read sensitive data, and cause a partial denial of service. The flaw is rooted in several weaknesses including missing authentication (CWE‑306), missing authorization (CWE‑862), improper access control (CWE‑284), and information exposure (CWE‑200).
Affected Systems
Oracle HCM Configuration Workbench, part of Oracle E‑Business Suite, is affected in supported versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS base score of 7.3 reflects moderate to high impact on confidentiality, integrity, and availability. The EPSS score is below 1%, indicating a low likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog. Attackers would need no authentication, merely HTTP access to the vulnerable component, making it potentially exploitable from the network, though not explicitly listed as a known exploit.
OpenCVE Enrichment