Impact
A flaw in the Oracle Quality Workbench HTML system allows a low‑privileged attacker with network access to the HTTP interface to perform unauthorized updates, inserts, deletes, and reads of Oracle Quality data. The vulnerability also permits the attacker to trigger a partial denial of service, affecting confidentiality, integrity, and availability of the system.
Affected Systems
The vulnerability impacts Oracle Corporation’s Oracle Quality component of Oracle E‑Business Suite for versions 12.2.3 through 12.2.15. These deployments expose an HTTP endpoint that does not enforce adequate privilege verification when handling data modification requests.
Risk and Exploitability
The CVSS 3.1 base score of 6.3 indicates moderate severity, with modest effects on confidentiality, integrity, and availability. The EPSS score of less than 1% suggests a low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a remote HTTP request from a low‑privileged source, requiring only network connectivity to the exposed Quality Workbench service and no elevated privileges.
OpenCVE Enrichment