Impact
A vulnerability in Oracle Data Integrator Studio allows a low‑privileged attacker who has logged on to the host to bypass authorization (CWE-269) and privilege escalation controls (CWE-863). The flaw enables full compromise of the application, resulting in loss of confidentiality, integrity, and availability for all data processed by the tool. The weakness is an example of improper access control (CWE-269) and privilege escalation (CWE-863).
Affected Systems
Oracle Data Integrator Studio versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability is in the Studio component of Oracle Fusion Middleware.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity weakness, but the EPSS shows a very low exploitation probability (<1%). The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only local access—an attacker with ordinary user rights can trigger the flaw without any additional permissions or user interaction, making the pathway straightforward for anyone who can log into the system where Oracle Data Integrator runs.
OpenCVE Enrichment