Impact
The vulnerability in Oracle Retail Integration Bus 14.1.3.2 (component RIB Kernel) is an Improper Authorization flaw (CWE‑284). An unauthenticated attacker can send crafted HTTP requests to the bus, resulting in full system compromise. The flaw permits remote code execution and takeover, compromising confidentiality, integrity, and availability.
Affected Systems
Oracle Retail Integration Bus version 14.1.3.2 from Oracle Corporation’s Retail Applications suite is the only product identified as vulnerable. No other versions or products are listed in the CVE data.
Risk and Exploitability
The CVSS v3.1 Base Score of 9.8 reflects critical severity across all dimensions, and the vector indicates network access, low complexity, no privileged user, and no user interaction. The EPSS score of less than 1% suggests that widespread exploitation is unlikely at present, and the vulnerability has not yet been listed in CISA KEV. Attackers can exploit the weakness from any location with HTTP access to the RIB bus, sending forged requests to bypass authentication and execute arbitrary commands.
OpenCVE Enrichment