Impact
This vulnerability in Oracle Time and Labor, part of Oracle E‑Business Suite, allows a low‑privileged attacker with network access via HTTP to create, modify, delete, or otherwise manipulate critical data, or to obtain unauthorized access to all data accessible by the application. The flaw results in a loss of confidentiality and integrity of the stored information. The weakness is an improper access control flaw.
Affected Systems
Affected versions are Oracle Time and Labor 12.2.3 through 12.2.15. The vulnerability applies to the Internal Operations component of Oracle Corporation’s Time and Labor product.
Risk and Exploitability
The base CVSS score of 8.1 highlights significant confidentiality and integrity impact. Despite the low EPSS (<1%) and absence from the CISA KEV catalog, the flaw remains easily exploitable over HTTP and requires only low privileged access. Attackers could forge unauthenticated HTTP requests to the Internal Operations component to perform unauthorized data manipulation or disclosure.
OpenCVE Enrichment