Impact
Oracle Data Integrator includes a Patchset Assistant that contains a security weakness. An attacker who has only low‑privilege logon access to the host where Oracle Data Integrator runs can exploit this flaw to bypass normal access controls and read any data the application can access. The vulnerability permits an unauthorized user to obtain confidential information but does not allow changes to the data or the system.
Affected Systems
Oracle Corporation’s Oracle Data Integrator, part of Oracle Fusion Middleware, is affected. The problematic versions are 12.2.1.4.0 and 14.1.2.0.0. These are the only releases explicitly cited in the advisory.
Risk and Exploitability
The CVSS base score of 6.5 marks the issue as medium severity, and the EPSS score of less than 1% indicates it is not yet widely exploited. The vulnerability is not listed in the CISA KEV catalog. Because exploitation requires only local low‑privileged access and the flaw can be used to read all data that the application can reach, the risk to organizations running the affected releases remains significant, especially if local accounts have unconstrained access or the system is exposed to potential local adversaries. The advisory notes a scope change, implying that compromise of Oracle Data Integrator could affect other Oracle products that interact with it.
OpenCVE Enrichment