Impact
The vulnerability is a low‑privilege, network‑accessible weakness in the Integration Business Insight component of Oracle SOA Suite. An attacker who can reach the system over HTTP can overwrite, delete, or create sensitive data without having administrative rights, thereby compromising confidentiality and integrity of all data exposed by the suite. The flaw is not an availability issue but offers an attacker full read/write control over the application’s data store.
Affected Systems
Oracle SOA Suite versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The weakness resides in the Integration Business Insight module of the Fusion Middleware stack.
Risk and Exploitability
The CVSS 3.1 base score of 9.6 classifies this as a critical flaw. The EPSS score of less than 1 % indicates that exploitation is currently rare, yet the high severity keeps the overall risk elevated. The vulnerability is not listed in CISA KEV. Exploitation requires only a low‑privilege attacker capable of sending crafted HTTP requests to reachable endpoints; no special hardware or privileged access is required.
OpenCVE Enrichment