Impact
Oracle Web Services Manager is affected by a vulnerability in the Web Services Security component that enables an unauthenticated attacker with network access via HTTP to create, delete, or modify critical data, as well as gain full access to all data exposed by the manager. The flaw is rated with a CVSS 3.1 Base Score of 9.1, indicating severe impacts on confidentiality and integrity with no impact on availability.
Affected Systems
The vulnerability applies to Oracle Corporation’s Web Services Manager version 12.2.1.4.0 and 14.1.2.0.0. No other vendors or products are listed as affected.
Risk and Exploitability
The flaw allows threat actors to exploit the system without authentication, using standard HTTP requests to trigger the abuse. The high CVSS score reflects the seriousness of the threat, yet the EPSS score is not available and the vulnerability is not currently catalogued in CISA KEV. Attackers can fully manipulate or acquire data exposed by Oracle Web Services Manager by leveraging the unauthenticated access path.
OpenCVE Enrichment