Impact
An insufficient access control flaw in Oracle Contract Lifecycle Management for Public Sector lets unauthenticated web users modify or read restricted data over HTTP. The weakness, categorized as CWE-284, permits unauthorized updates, inserts, or deletions, as well as read access to subsets of the system’s data. This can compromise the integrity and confidentiality of the application’s information.
Affected Systems
The vulnerability impacts Oracle’s Contract Lifecycle Management for Public Sector product, specifically the Wage Determination Online component, across versions 12.2.3 to 12.2.15. Users of these releases are exposed to potential data tampering or unauthorized data disclosure.
Risk and Exploitability
The CVSS v3.1 base score of 6.1 scores moderate risk for confidentiality and integrity. The exploit probability according to the EPSS is below 1 %, and the flaw is not listed in the CISA KEV catalog. It is exploitable by a network-remote attacker over HTTP, but requires human interaction to activate the malicious actions. The attack vector is therefore a network-based one, and while the flaw resides in the Contract Lifecycle Management product, the impact may extend to other Oracle E-Business Suite components.
OpenCVE Enrichment