Impact
A vulnerability exists in Oracle Work in Process, part of Oracle E‑Business Suite. The flaw allows an attacker with low privileges and network access via HTTP to perform unauthorized updates, inserts, or deletions, as well as read restricted data. The attacker must interact with a user other than themselves, implying that successful exploitation requires some level of social engineering or user cooperation. Because the vulnerability can change the scope of the affected system, its impacted integrity and confidentiality can extend beyond the immediate product. This results in the loss or corruption of data that is normally protected by the application’s access controls.
Affected Systems
The product affected is Oracle Work in Process within Oracle E‑Business Suite. Versions 12.2.5 through 12.2.15 are vulnerable. These versions include the internal operations component, which handles critical business data and processes.
Risk and Exploitability
The CVSS v3.1 base score is 5.4, indicating a moderate level of risk. The EPSS score is less than 1%, showing a low probability of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network via HTTP and requires the attacker to have low privileges and to obtain user interaction. While the risk is moderate, the potential to change the scope of the impact means it can affect other Oracle products if the attacker gains broader access.
OpenCVE Enrichment