Impact
An unauthenticated attacker with network access via HTTP can exploit a flaw in the Workflow Notification Mailer component of Oracle Workflow, causing the application to hang or crash repeatedly. The result is a complete denial of service that disrupts all Oracle Workflow processing. The CVSS base score of 7.5 reflects a high impact on availability, while compromising confidentiality or integrity is not described.
Affected Systems
Oracle Workflow from Oracle E‑Business Suite, specifically the Workflow Notification Mailer component, is impacted in versions 12.2.3 through 12.2.15. Users of these releases should verify their installed version against the affected range.
Risk and Exploitability
The vulnerability is easily exploitable, requiring only unauthenticated HTTP requests, which indicates the attacker can engage the flaw remotely. However, the EPSS score of less than 1% suggests a very low probability of real-world exploitation. Because the issue leads to application crashes, the risk is substantial for environments that depend on uninterrupted workflow processing. Since the vulnerability is not listed in the CISA KEV catalog, the potential for exploitation remains uncertain, but an attacker can achieve a denial of service without any pre‑existing credential, making the attack vector straightforward.
OpenCVE Enrichment