Impact
A flaw in the Internal Operations component of Oracle Product Workbench allows an attacker with low privileges but network access over HTTP to bypass intended access controls. The vulnerability can be exploited to create, delete, or modify critical data or to gain full access to all data the product handles, thereby exposing the system to both confidentiality and integrity violations as reflected in the CVSS vector.
Affected Systems
Oracle Product Workbench versions 12.2.3 through 12.2.15 are affected. The flaw exists in the Internal Operations component of Oracle E‑Business Suite, and the only prerequisite for exploitation is a network connection to the application over HTTP.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 indicates a high severity flaw. EPSS is reported as less than 1 %, suggesting that the likelihood of exploitation in the wild is very low at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires only standard HTTP connectivity and low privileges, so an attacker who can reach the target system can immediately exercise the erroneous access control and perform unauthorized data modifications.
OpenCVE Enrichment