Impact
A vulnerability in the Oracle Security Service product of Oracle Fusion Middleware allows a low‑privileged attacker with HTTPS network access to compromise the service. The flaw can result in unauthorized creation, deletion or modification of critical data and can grant unauthorized access to all data accessible through the Oracle Security Service. The weakness is related to improper access control and can affect confidentiality and integrity of the system.
Affected Systems
Oracle Corporation Oracle Security Service 12.1.3.0.0 and 12.2.1.4.0 are affected.
Risk and Exploitability
The CVSS 3.1 base score of 6.4 indicates a moderate severity with high impact on confidentiality and integrity, while the standard attack vector is network based (HTTPS). The vulnerability has a high attack complexity and low privileges, and requires user interaction, which makes exploitation difficult but still possible. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment