Impact
This vulnerability is a resource exhaustion flaw in the Internal Operations component of Oracle Time and Labor, part of Oracle E‑Business Suite. It allows a low‑privilege attacker who can reach the application over HTTP to exploit the flaw and cause a partial denial of service. The weakness is identified as CWE‑400 and results in degraded availability of the application, but does not expose confidential data or alter integrity. The impact is confined to the affected Oracle Time and Labor instance and is limited to a reduction or interruption of service availability.
Affected Systems
Oracle Time and Labor versions 12.2.3 through 12.2.15 are affected. The flaw exists within the Internal Operations component of the Oracle E‑Business Suite product and applies to systems deployed with these version ranges.
Risk and Exploitability
The CVSS base score of 3.1 indicates a low severity impact on availability, and the EPSS score of less than 1% signals a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, reinforcing its low exposure. An attacker would need network access to the application’s HTTP interface and only require low privileges to launch an attack that could degrade availability.
OpenCVE Enrichment