Impact
The Oracle HCM Configuration Workbench vulnerability permits a low‑privileged attacker with network access via HTTP to perform unauthorized insert, update, or delete operations on configuration data, to read restricted data subsets, and to trigger a partial denial of service. The weakness involves improper access control, SQL injection, and information exposure (CWE‑284, CWE‑89, CWE‑200).
Affected Systems
Affected vendors are Oracle Corporation, specifically the Oracle HCM Configuration Workbench component of Oracle E-Business Suite. The vulnerability impacts versions ranging from 12.2.3 through 12.2.15.
Risk and Exploitability
With a CVSS 3.1 base score of 6.3 and an EPSS score of less than 1 %, the exploitation probability is low but not negligible. The vulnerability is not listed in the CISA KNOWN EXPLOITED VULNERABILITIES catalog. The likely attack vector is HTTP requests sent to the configuration web interface, requiring only a low‑privilege account but granting significant read/write privileges and the ability to disrupt service.
OpenCVE Enrichment