Impact
The vulnerability exists in the Oracle Product Workbench WebUI component and permits a low‑privileged attacker with HTTP network access to modify, insert, or delete data, as well as read restricted information. The flaw requires the attacker to compel another user to interact, enabling unauthorized access to data that should be protected by proper authorization controls.
Affected Systems
Oracle Product Workbench, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected. The vulnerability may also influence other Oracle products because of a scope change.
Risk and Exploitability
The CVSS 3.1 base score of 5.4 indicates moderate effects on confidentiality and integrity, while the EPSS score below 1% suggests a low probability of exploitation. The flaw is not listed in CISA’s KEV catalog. Successful exploitation requires network connectivity to the Product Workbench WebUI and the cooperation of a separate user, after which the attacker can modify, delete, or read data and potentially impact other Oracle applications due to the scope change.
OpenCVE Enrichment