Impact
A vulnerability in Oracle Time and Labor’s Internal Operations component allows an attacker who already has high privileges on the network to perform unauthorized creation, modification, or deletion of critical data. The flaw also permits full unauthorized access to all data stored in Oracle Time and Labor and can be used to induce a partial denial of service. The weakness results in high impact to confidentiality, integrity, and low impact to availability, as reflected by the CVSS‑3.1 vector (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L).
Affected Systems
Oracle Time and Labor, part of Oracle E‑Business Suite, is affected in versions 12.2.3 through 12.2.15. The issue resides in the Internal Operations component, which is exposed via HTTP and requires high‑level credentials to exploit.
Risk and Exploitability
The CVSS base score of 6.7 indicates a moderate to high risk. EPSS is below 1%, meaning current exploitation probability is very low, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, an attacker who can reach the system over HTTP and who has high‑privilege credentials can immediately execute the flaw and gain unauthorized data access or cause service disruption. The required network access and elevated privileges reduce the attack surface, but once those prerequisites are met, the vulnerability is easily exploitable and has significant damage potential.
OpenCVE Enrichment