Impact
This vulnerability in Oracle Time and Labor allows a low-privileged attacker who can reach the application over HTTP to create, delete or modify critical data. The flaw stems from an improper access-control check (CWE-284) that lets the attacker bypass authorization requirements when exercising operations on internal data. Successful exploitation would not provide code execution or denial of service; it would specifically compromise the integrity of data that the application processes.
Affected Systems
Oracle Time and Labor component Internal Operations for Oracle E-Business Suite versions 12.2.3 through 12.2.15 are impacted. All installations of these versions should be verified for the issue.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate impact exclusively on integrity. The EPSS score is reported as < 1%, meaning the likelihood of exploitation is very low and the vulnerability is not listed in the CISA KEV catalog. The attack route requires network access over HTTP, low-privilege authentication, and exploitation of the missing authorization check. Because the vulnerability does not provide remote code execution or privilege escalation beyond the attacker’s existing level, the overall risk remains moderate but should still be addressed promptly.
OpenCVE Enrichment