Impact
This issue is a flaw in the REST service component of Oracle Data Integrator that allows an unauthenticated attacker with simple network access to the HTTP port to fully compromise the application. The vulnerability is tied to improper access control, where the service fails to enforce authentication and authorization for sensitive operations, permitting arbitrary manipulation of data and configuration. Successful exploitation results in complete loss of confidentiality, integrity and availability of the system, with the CVSS 3.1 vector indicating a base score of 10.0 for all three impact dimensions. The vulnerability also maps to CWE-306, indicating a missing authentication for a sensitive function.
Affected Systems
Oracle Corporation’s Oracle Data Integrator, versions 12.2.1.4.0 and 14.1.2.0.0, are affected. No other vendors or products are listed in the current advisory.
Risk and Exploitability
The CVSS score of 10.0 places this vulnerability in the highest severity band. The EPSS score is noted as <1%, indicating a low probability of exploitation in observed incidents, but that does not diminish the potential damage. Attackers can reach the vulnerable REST API over the network without authentication, making manual or automated exploitation straightforward. The flaw relates to improper access control and missing authentication for a sensitive function (CWE-306). The vulnerability’s scope change flag suggests that other components in the Oracle Fusion Middleware stack could also be impacted if exposed through the same REST channels. The vulnerability is not included in the CISA KEV catalog, so no known active exploitation is confirmed yet. Nevertheless, given its high impact, the risk is considered critical.
OpenCVE Enrichment