Impact
A vulnerability in Oracle Data Integrator Studio permits a low‑privileged attacker who can log into the underlying infrastructure to gain full control of the appliance. The flaw enables an attacker to compromise the application, resulting in loss of confidentiality, integrity, and availability of all data processed by the tool. The weakness is an example of improper access control or missing authorization.
Affected Systems
Oracle Data Integrator Studio versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability is present in the Studio component of Oracle Fusion Middleware.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity weakness, but the EPSS shows a very low exploitation probability (<1%). The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only local access—an attacker with ordinary user rights can trigger the flaw without any additional permissions or user interaction, making the pathway straightforward for anyone who can log into the system where Oracle Data Integrator runs.
OpenCVE Enrichment