Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Loader). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Workflow. While the vulnerability is in Oracle Workflow, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpuapr2026.html |
|
History
Wed, 22 Apr 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authorization Bypass in Oracle Workflow Loader Enables Data Tampering and Partial Denial of Service | |
| Weaknesses | CWE-285 |
Wed, 22 Apr 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authorization Bypass in Oracle Workflow Allows Unauthorized Data Modification and Partial Denial of Service | |
| Weaknesses | CWE-284 CWE-285 |
Wed, 22 Apr 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authorization Bypass in Oracle Workflow Allows Unauthorized Data Modification and Partial Denial of Service | |
| Weaknesses | CWE-284 CWE-285 |
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Loader). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Workflow. While the vulnerability is in Oracle Workflow, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L). | |
| First Time appeared |
Oracle
Oracle workflow |
|
| CPEs | cpe:2.3:a:oracle:workflow:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle workflow |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-04-21T20:35:32.038Z
Reserved: 2026-03-26T19:48:45.678Z
Link: CVE-2026-34302
No data.
Status : Received
Published: 2026-04-21T21:16:35.410
Modified: 2026-04-21T21:16:35.410
Link: CVE-2026-34302
No data.
OpenCVE Enrichment
Updated: 2026-04-22T07:30:11Z