Impact
This vulnerability allows a low‑privileged attacker with network access via HTTP to exploit the Internal Operations component of Oracle Work in Process and gain full control of the application, compromising confidentiality, integrity, and availability through an easily exploitable path that requires no user interaction.
Affected Systems
Oracle Work in Process versions 12.2.3 through 12.2.15 of Oracle E‑Business Suite are affected; the flaw resides in the Internal Operations module of the Work in Process component.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates a high‑severity impact on all core security properties. The EPSS score is less than 1% and the vulnerability is not listed in CISA KEV, suggesting limited publicly observed exploitation; nevertheless, the attack requires only low‑privilege network access to the HTTP endpoint, making the risk significant for exposed systems.
OpenCVE Enrichment