Impact
Oracle Work in Process, a component of Oracle E‑Business Suite, contains an easily exploitable flaw that can be triggered over HTTP by a low‑privileged attacker. When successfully exploited, it allows the attacker to update, insert, or delete data stored in Work in Process and to cause the application to hang or repeatedly crash, resulting in both integrity and availability compromises.
Affected Systems
The vulnerability affects the Oracle Work in Process product, specifically its Internal Operations component, across all supported E‑Business Suite releases from 12.2.3 through 12.2.15. Users running any of these versions with the Work in Process component exposed to HTTP are at risk.
Risk and Exploitability
The flaw carries a CVSS 3.1 base score of 7.1, indicating moderate severity. Attackers only need network access to the Work in Process HTTP interface and, due to the low privilege requirement, can exploit the issue even from a compromised device within the trusted network. The EPSS score is less than 1%, suggesting a low probability of current exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the potential for repeated crashes and unauthorized data modification makes it a significant threat for exposed systems.
OpenCVE Enrichment