Impact
An unauthenticated attacker can exploit a flaw in the Oracle Workflow Notification Mailer through SMTP traffic, enabling an attacker to gain full control over the Oracle Workflow instance. The vulnerability permits remote exploitation without authentication or user interaction, leading to complete compromise of confidentiality, integrity, and availability of the affected system.
Affected Systems
Oracle Corporation’s Oracle Workflow product, part of Oracle E‑Business Suite, is vulnerable. All releases from 12.2.3 to 12.2.15 are affected, specifically the Workflow Notification Mailer component.
Risk and Exploitability
The CVSS score of 9.8 reflects a high‑severity risk with a network attack vector, low complexity, no required privileges or user interaction, and complete impact on the system. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this issue remotely via SMTP without prior compromise, so the risk is immediate and significant.
OpenCVE Enrichment