Impact
The vulnerability is located in the Internal Operations component of Oracle Product Workbench within Oracle E‑Business Suite. It allows an attacker who is low‑privileged but has network access via HTTP to create, delete, or modify data that the application can access. Successful exploitation results in the loss of confidentiality and integrity for all data handled by Oracle Product Workbench, without affecting availability.
Affected Systems
Affected systems are Oracle Product Workbench versions 12.2.3 through 12.2.15, inclusive. The flaw exists in all releases of the specified version range within the Internal Operations component of Oracle E‑Business Suite.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates high severity, reflecting the serious confidentiality and integrity impact. The EPSS score of less than 1% suggests that in the wild the exploitation probability is very low, and the issue is not currently listed in the CISA KEV catalog. Externally the attacker would need direct visibility to the product’s HTTP interface and the ability to authenticate with low‑privilege credentials, which is sufficient to trigger data‑manipulation attacks under the stated conditions.
OpenCVE Enrichment