Impact
The Oracle Time and Labor product in the Internal Operations component contains an authorization bypass flaw that permits a low‑privileged attacker with HTTP network access to create, delete, or modify critical data. An attacker who can reach the application over HTTP can also gain unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data as well as unauthorized access to critical data or complete access to all Oracle Time and Labor accessible data. This leads to confidentiality and integrity compromise, as reflected by a CVSS vector with high confidentiality and high integrity impacts.
Affected Systems
Affected installations are Oracle Time and Labor releases version 12.2.3 through 12.2.15. Versions outside this range are not documented as affected in the current advisory.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates a high‑severity vulnerability with significant confidentiality and integrity impacts. The EPSS score of less than 1% suggests a low probability of exploitation currently, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑based HTTP request from an attacker who has low‑privileged access to the system. Successful exploitation requires the attacker to be able to send HTTP traffic to the vulnerable service.
OpenCVE Enrichment