Impact
A flaw in the Oracle Workflow Notification Mailer allows an attacker who can reach the service over HTTP to perform unauthorized create, read, update and delete operations on Workflow data and to cause a partial service outage. The vulnerability gives the attacker both read and write capabilities on a subset of Workflow data while also exposing the system to a potential denial of service.
Affected Systems
Oracle Corporation’s Oracle Workflow product in Oracle E‑Business Suite is affected. Versions 12.2.3 through 12.2.15 of the Workflow component are vulnerable. Applications running these versions should be reviewed to confirm they host the affected component.
Risk and Exploitability
The CVSS v3.1 base score of 6.3 indicates moderate severity with low or moderate impacts on confidentiality, integrity and availability. The EPSS score indicates an exploitation probability of less than 1 %. The vulnerability is not listed in the CISA KEV catalog, which suggests no known, actively exploited instances. The attack vector is limited to network traffic over HTTP, which requires the attacker to have network access to the Workflow service. Given these factors, the risk remains moderate, but the presence of a low‑privilege attacker on the network justifies prompt remediation.
OpenCVE Enrichment