Impact
A flaw in Oracle SOA Suite’s Integration Business Insight component allows an attacker with low privileges and network access via HTTP to obtain unauthorized access to critical data. The vulnerability enables the adversary to read data stored in the SOA environment; because the CVSS vector indicates a scope change, a successful compromise may also affect additional components within the SOA deployment, potentially broadening the data exposure.
Affected Systems
Oracle SOA Suite versions 12.2.1.4.0 and 14.1.2.0.0, as identified by Oracle in their CPU July 2026 advisory, are impacted by this issue.
Risk and Exploitability
The CVSS 3.1 score of 7.7 classifies the vulnerability as high severity. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and it is not listed in the CISA KEV catalog. An attacker only needs network connectivity to the exposed HTTP endpoint and does not require any special privileges beyond a low‑privilege account, making the exploitation path simple for a network‑reachable adversary.
OpenCVE Enrichment