Impact
The flaw resides in the Integration Business Insight component of Oracle SOA Suite. An attacker who can reach the system over HTTP and possesses high‑privilege credentials can exploit the weakness, leading to violations of confidentiality, integrity, and availability and ultimately achieving full takeover of the entire SOA Suite instance.
Affected Systems
Oracle SOA Suite versions 12.2.1.4.0 and 14.1.2.0 are affected by the vulnerability.
Risk and Exploitability
The CVSS 3.1 base score of 7.2 reflects a medium‑to‑high severity, with full control possible if successfully exploited. The EPSS score of less than 1% indicates that, as of now, exploitation appears unlikely, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be network‑based HTTP requests to a privileged endpoint within the Integration Business Insight component, and the attacker must already possess high privileges to perform the exploitation.
OpenCVE Enrichment