Impact
This vulnerability resides in the Enterprise Scheduling System component of Oracle SOA Suite and allows an unauthenticated attacker to exploit the application over an HTTP network connection. The flaw is an improper authentication bypass, enabling the attacker to gain full control of the application, resulting in complete compromise of confidentiality, integrity, and availability of the targeted system.
Affected Systems
Oracle SOA Suite 12.2.1.4.0 and 14.1.2.0.0 from Oracle Corporation are affected. These versions are part of the Oracle Fusion Middleware suite.
Risk and Exploitability
According to the CVSS v3.1 score of 9.8, this is a critical vulnerability. The EPSS score of less than 1 percent indicates that exploitation is currently unlikely but could still occur, particularly if the SOA Suite instance is exposed to the Internet and the attacker has network access. The vulnerability is not yet listed in the CISA KEV catalog. Attackers do not require user interaction or privileges, making it easily exploitable via standard HTTP requests.
OpenCVE Enrichment