Impact
Oracle Labor Distribution, part of Oracle E‑Business Suite, contains a weakness that allows a low‑privileged attacker with network access via HTTP to modify critical data. The flaw is a classic authorization bypass, enabling the attacker to create, delete, or alter records and to read any data the application can access. The result is significant exposure of confidential and integrity‑sensitive information, with no documented availability impact.
Affected Systems
The issue affects all supported releases of Oracle Labor Distribution from version 12.2.3 through 12.2.15. Users of the Internal Operations component are exposed, and any system with HTTP exposure to the Labor Distribution interface may be vulnerable.
Risk and Exploitability
The vulnerability has a CVSS 3.1 base score of 8.1, reflecting high severity due to the combination of network proximity, low authentication, and the ability to compromise confidentiality and integrity. Exploitation requires only low privileges and can be performed over standard HTTP traffic, making the attack vector readily achievable from the network. EPSS score is <1%, indicating a very low probability of exploitation at this time, and the flaw is not listed in the CISA KEV catalog, but the high score and the minimal privilege requirement still present a realistic threat.
OpenCVE Enrichment