Impact
The vulnerability is an authentication bypass that allows an attacker with physical access to the network segment attached to the hardware where Oracle Work in Process runs to gain unrestricted access. Once accessed, the attacker can create, delete, or modify any data within the application, compromising both confidentiality and integrity of critical information. The flaw is classified as an access control weakness.
Affected Systems
Oracle Work in Process product in Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, used in the Workbenches component. The vendor is Oracle Corporation.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates a high risk level, while the EPSS score of less than 1% denotes a currently low likelihood of exploitation. The vulnerability is not listed in CISA KEV. The attack requires physical network access to the hardware where Oracle Work in Process executes; once accessed, the attacker can perform arbitrary data operations without authentication.
OpenCVE Enrichment