Impact
A vulnerability in the Oracle Workflow Notification Mailer permits an unauthenticated attacker with network access to the SMTP service to compromise Oracle Workflow. The flaw allows an attacker to gain full control of the Workflow instance, leading to the exposure of all data and modification of business processes. The weakness is rooted in authentication failures and insufficient validation associated with incoming mail streams, aligning with CWE-287 and CWE-306. The impact is comprehensive, affecting confidentiality, integrity, and availability of the affected systems after exploitation.
Affected Systems
Oracle Corporation’s Oracle Workflow component of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, are affected. These variants receive e‑mail notifications via SMTP and are vulnerable when messages are processed without proper authentication checks.
Risk and Exploitability
The CVSS 3.1 Base score of 8.1 indicates high severity, yet the EPSS score is reported as less than 1%, suggesting a very low probability of exploitation in the wild. This vulnerability is not listed in the CISA KEV catalog. Likely attackers would need network connectivity to the system’s SMTP endpoint; despite the difficulty in exploitation, the potential gain of full workflow control warrants immediate attention.
OpenCVE Enrichment