Impact
Vulnerability in Oracle Data Integrator allows an attacker logged into the host where the software runs to compromise it and perform unauthorized creation, deletion, or modification of critical data. This flaw is an instance of CWE-284 (Improper Access Control) and leads to significant confidentiality and integrity impact, as indicated by the CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N). Successful exploitation lets an attacker access all critical data available through the affected Data Integrator installation. The description does not explicitly state the level of access beyond this scope.
Affected Systems
Oracle Data Integrator versions 12.2.1.4.0 and 14.1.2.0.0 on the Oracle Fusion Middleware stack are affected. These installations run on infrastructure where users have local logon capability; the vulnerability is specific to the Market Place component of the product.
Risk and Exploitability
The CVSS base score of 8.4 denotes high severity, while the EPSS score of less than 1% indicates low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, yet its scope change could impact other Oracle products. Attackers only need low‑privilege local access, making it relatively easy to exploit compared to remote attacks.
OpenCVE Enrichment