Impact
This vulnerability is a CWE‑284 broken access control flaw that allows an unauthenticated attacker who can reach the Oracle Retail EFTLink service over HTTPS to create, delete, or modify critical data. Because authentication is not required, the attacker can also gain read access to all information that the EFTLink component exposes. The flaw results in significant confidentiality and integrity breaches for any organization running affected versions of the product.
Affected Systems
Oracle Retail EFTLink by Oracle Corporation, versions 21.0.0 through 25.0.0 are affected.
Risk and Exploitability
The CVSS base score of 7.4 and an EPSS score of less than 1% indicate that while the vulnerability is moderately severe, it is not highly likely to be exploited. The flaw is reachable via standard HTTPS traffic, and no authentication is needed, making it a straightforward remote exploitation path for attackers with network access to the EFTLink service. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.
OpenCVE Enrichment