Impact
The flaw in the B2B Engine component of Oracle SOA Suite allows an unauthenticated attacker who can reach the system over HTTP to compromise the application. This vulnerability results in unauthorized access to critical data or full access to all data normally available to authorized users, and it also enables the attacker to cause a partial denial‑of‑service of Oracle SOA Suite. The weakness is an improper access control flaw that impacts confidentiality and availability.
Affected Systems
Affected products are Oracle SOA Suite versions 12.2.1.4.0 and 14.1.2.0.0.
Risk and Exploitability
The CVSS score of 8.2 indicates high risk, but the EPSS score of less than 1% shows a low yet non‑zero probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. An attacker only needs network connectivity to the HTTP service to exploit this flaw; no special credentials or elevated privileges are required.
OpenCVE Enrichment