Impact
Oracle Product Workbench’s WebUI permits any low‑privileged HTTP attacker to bypass authorization controls and gain unauthorized create, read, update, and delete access to a subset of data, as well as cause a partial denial of service. The weakness is an access control flaw (CWE‑284) that allows unauthorized manipulation of data and disruption of service without user interaction.
Affected Systems
The affected product is Oracle Product Workbench from Oracle Corporation, versions 12.2.3 through 12.2.15. These releases are web interface exposed over HTTP.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, with low confidentiality, integrity, and availability impacts. The EPSS value of less than 1% suggests a small likelihood of exploitation in the wild, and it is not listed in the CISA KEV catalog. Attackers can exploit the flaw to the WebUI, using only low privileges, so the risk remains significant for exposed instances.
OpenCVE Enrichment