Impact
A vulnerability in Oracle SOA Suite’s Integration Business Insight component allows an attacker with low privileges and network access via HTTP to execute code and take full control. The flaw is easily exploitable and can lead to complete compromise of the SOA Suite instance, exposing or altering confidential data and disrupting all services.
Affected Systems
The affected product is Oracle SOA Suite from Oracle Corporation, specifically versions 12.2.1.4.0 and 14.1.2.0.0. These releases are part of the Oracle Fusion Middleware stack.
Risk and Exploitability
The CVSS v3.1 ranking is 8.8 with a vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating a high severity. The EPSS score is less than 1 % and the vulnerability is not listed in CISA’s KEV catalog, suggesting that while exploitation is unlikely at present, the low attack effort and network exposure provide an opportunity for attackers. The remote HTTP interface can be targeted by adversaries who already have network reach, without the need for privileged credentials or additional pre‑conditions.
OpenCVE Enrichment