Impact
Oracle Product Workbench in Oracle E‑Business Suite contains a flaw in the Internal Operations component that allows a low‑privileged attacker with network access over HTTP to create, delete, modify, or access critical data without proper authorization. The vulnerability can lead to a loss of confidentiality and integrity for all data available through Product Workbench, effectively giving an attacker unchecked access to the entire data set. The weakness is categorized as improper access control (CWE‑284).
Affected Systems
Oracle Product Workbench versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The CVSS Base Score of 8.1 marks this as a high severity flaw. The EPSS score of less than 1% indicates a low probability of current exploitation. An attacker does not need privileged access or to execute code; simply sending HTTP requests from a low‑privilege account to the web interface is sufficient to exploit the flaw. The vulnerability is not listed in the CISA KEV catalog and no active exploitation has been reported.
OpenCVE Enrichment