Impact
The flaw lies in Oracle Work in Process, part of the Oracle E‑Business Suite, where an attacker who can log into the same infrastructure may use local privileges to compromise the application. The effect is a full takeover of Oracle Work in Process, resulting in complete loss of confidentiality, integrity, and availability for that component. The weakness is an improper access control flaw.
Affected Systems
Oracle Corporation’s Work in Process component of Oracle E‑Business Suite is affected. Versions 12.2.3 through 12.2.15 are vulnerable. The vulnerability is present in the internal operations part of the product.
Risk and Exploitability
The CVSS v3.1 base score of 7.0 indicates a substantial risk. The exploit requires only a local logon with low privileges, meaning a local attacker could compromise Work in Process and gain full control. The EPSS score is below 1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Given that local access is required, any host that an attacker can log into poses a realistic attack surface; the combination of confidentiality, integrity, and availability impacts and the relative ease of local exploitation places the vulnerability at a high threat level for affected environments.
OpenCVE Enrichment