Impact
A vulnerability in Oracle Product Workbench allows a low‑privileged attacker with network access via HTTP to create, delete, modify, or otherwise manipulate critical data. The flaw grants unauthorized creation, deletion, or modification access to critical data, as well as the ability to access all data the product can reach, compromising both confidentiality and integrity of the system.
Affected Systems
Oracle Corporation’s Product Workbench component of Oracle E-Business Suite, specifically the Internal Operations module, is affected in versions 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity with substantial confidentiality and integrity impact. The EPSS score of <1% indicates a low probability of exploitation, yet it still represents a reported risk, and the vulnerability is not currently listed in CISA’s KEV catalog. The attack vector is network‑based, requiring only low‑privilege credentials and HTTP access to the product, making the vulnerability potentially easily exploitable by attackers who can reach the target system over the network.
OpenCVE Enrichment