Impact
Vulnerability in Oracle Data Integrator's Patchset Assistant component permits an unauthenticated attacker with network access via HTTP to gain unauthorized access to all data exposed by the application. The flaw results in data confidentiality compromise, with the attacker able to read or modify critical information without requiring prior authentication. This exposure is due to an access control weakness that allows unrestricted entry to privileged functionality. The impact is limited to confidentiality, but the potential loss of sensitive data can be significant for organizations relying on Oracle Data Integrator for data integration and processing workflows.
Affected Systems
Oracle Corporation's Data Integrator product in the Oracle Fusion Middleware suite is affected. Supported versions that contain the vulnerability are 12.2.1.4.0 and 14.1.2.0.0. If your environment runs either of these releases, the product is susceptible to exploitation until a security update is applied.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 reflects a moderate to high risk, driven by the high confidentiality impact. The EPSS score of less than 1% indicates that, while the vulnerability exists, the probability of public exploitation remains low at present. It is not listed in the CISA KEV catalog, suggesting no known widespread active exploitation. However, the attacker does not require any privileges or special configuration; a simple HTTP request to the vulnerable endpoint is sufficient. Organizations with open network exposure to Oracle Data Integrator should consider that exploitation could occur quickly if the vulnerability is discovered and a tool is released.
OpenCVE Enrichment