Impact
A CWE-200 information‑exposure flaw in the general component of Oracle REST Data Services allows an unauthenticated attacker who can reach the service over HTTPS to read a subset of data exposed by the service. The flaw does not modify data or disrupt service operation. Impact is limited to confidentiality, as reflected by the CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N.
Affected Systems
Oracle REST Data Services versions 24.2.0 through 26.1.0 are affected. The vulnerability resides in the general component of the product.
Risk and Exploitability
The CVSS base score of 5.3 indicates a medium severity. However, the EPSS score of <1% suggests a very low probability of exploitation in the wild. The lack of authentication requirement means a network attacker could easily attempt the attack, but the combination of a low EPSS and the need for direct HTTPS connectivity mitigates the overall risk. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment