Impact
A operations component of Oracle Work in Process allows a low‑privileged attacker with network access over HTTP to create, delete or modify critical data. The vulnerability results in unauthorized creation, deletion or alteration of data and full access to all data that the product can reach. This is an authorization bypass weakness (CWE‑284) that directly threatens confidentiality and integrity of enterprise data.
Affected Systems
Oracle Corporation’s Oracle Work in Process product is affected. Oracle E‑Business Suite versions 12.2.14 and 12.2.15 contain the vulnerability. The flaw exists in the internal operations component of the Work in Process service.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 denotes an impact on confidentiality and integrity. The EPSS score of < 1% indicates a low probability of active exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires only network access to the HTTP interface and low user privileges, making it a relatively easy attack path for an attacker with network visibility.
OpenCVE Enrichment