Impact
The Oracle Workflow Notification Mailer component in Oracle E‑Business Suite contains an authorization flaw. A low‑privileged attacker who can reach the application over HTTP can exploit the flaw to create, delete, or modify critical data accessed through Oracle Workflow. The same flaw also enables the attacker to cause the service to or repeatedly crash, resulting in a complete denial of service.
Affected Systems
Oracle Workflow versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates high severity with significant integrity and availability impact. Because the attack is network‑based via HTTP and only requires low privileges, the vulnerability is likely easily exploitable. The EPSS score of 0.00404 indicates a very low exploit probability, and the flaw is not listed in CISA’s KEV catalog, yet its combination of exploitability and damage potential warrants urgent attention.
OpenCVE Enrichment