Impact
The vulnerability in Oracle Retail Integration Bus represents a CWE-284 Improper Access Control flaw. It allows an unauthenticated attacker with HTTP network access to fully compromise the system, exposing all data and control capabilities. This flaw results in loss of confidentiality, integrity, and availability, effectively giving the attacker full administrative control of the integration bus.
Affected Systems
Oracle Retail Integration Bus version 16.0.3 is affected. No other versions were listed by Oracle or in the available data.
Risk and Exploitability
The CVSS score of 9.8 emphasizes the severity of the flaw, and the EPSS score of less than 1% suggests exploitation probability is presently low, though it remains low‑complexity and requires no user interaction. Because the attack vector is network and the access requirement is none, an attacker can trigger the vulnerability by sending a crafted HTTP request to the target. The flaw is not listed in CISA’s KEV catalog, but the lack of authentication and network scope make it a high‑risk exposure for any customer running the vulnerable version.
OpenCVE Enrichment