Impact
The vulnerability in Oracle Product Workbench is a privilege escalation flaw that enables a low‑privileged attacker who can reach the system via HTTP to compromise the entire application. This weakness, classified as CWE‑269, can lead to a full takeover of Oracle Product Workbench, resulting in loss of confidentiality, integrity, and availability. The CVE advisory indicates that successful exploitation could also cause a scope change, allowing the attacker to affect additional components of Oracle E‑Business Suite.
Affected Systems
Affected products are Oracle Corporation’s Product Workbench in the E‑Business Suite, specifically versions 12.2.3 through 12.2.15. No other vendors or product lines are listed in the advisory.
Risk and Exploitability
The CVSS 3.1 base score of 8.5 marks a high‑severity risk across confidentiality, integrity, and availability, while the EPSS score of less than 1% suggests a low exploitation probability in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker’s likely vector is standard HTTP traffic directed at the internal operations component, requiring only low privileged access and moderate technical skill to construct the exploit.
OpenCVE Enrichment