Impact
Oracle SOA Suite contains a flaw in its Enterprise Scheduling System that lets an unauthenticated attacker send crafted HTTP requests to the system. The absence of authentication checks allows the attacker to execute arbitrary code on the host, resulting in a full takeover of the affected Oracle SOA Suite instance. This compromises confidentiality, integrity, and availability.
Affected Systems
This issue affects Oracle Corporation’s Oracle SOA Suite (Oracle Fusion Middleware) versions 12.2.1.4.0 and 14.1.2.0.0. The vulnerability resides in the Enterprise Scheduling System component of these releases.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 indicates a severe impact on all three core security properties. The EPSS score of less than 1% suggests exploitation is currently unlikely, and it is not listed in the CISA KEV catalog. Nonetheless, the vulnerability is described as easily exploitable. If an attacker can reach the affected Enterprise Scheduling System over HTTP from an unauthenticated position, they can run arbitrary code and fully compromise the appliance.
OpenCVE Enrichment