Impact
A flaw in Oracle REST Data Services Core enables a low‑privileged attacker who can reach the service over HTTPS to fully compromise the application. The vulnerability allows disclosure of all data, modification of any data, and complete control of the service, effectively resulting in a full takeover. It carries a CVSS 3.1 Base Score of 9.9 and impacts confidentiality, integrity, and availability.
Affected Systems
Affected product: Oracle REST Data Services. Versions impacted are 24.2.0 through 26.1.0. The issue resides in the Core component of the product.
Risk and Exploitability
The exploit is considered easily actionable; the attack vector is via network‑bound HTTPS traffic and requires only low or no privileges. Because the vulnerability changes scope, successful compromise could affect other Oracle products that rely on the service. The current EPSS score is not available, and the vulnerability is not yet listed in CISA KEV, but the high CVSS combined with the potential for complete takeover underscores a serious risk if left unmitigated.
OpenCVE Enrichment