Impact
Oracle Web Services Manager is vulnerable in its Web Services Security component, allowing an unauthenticated attacker with network access via HTTP to create, delete, or modify critical data and gain full access to all data exposed by the manager. The flaw is an example of weak access control (CWE-284) and results in severe impacts on confidentiality and integrity with no availability impact, as reflected by the CVSS 3.1 Base score of 9.1.
Affected Systems
The vulnerability applies to Oracle Web Services Manager versions 12.2.1.4.0, 14.1.2.0.0, and 14.1.2.1.0. No other vendors or products are listed as affected.
Risk and Exploitability
The vulnerability permits attackers to act without prior authentication, using standard HTTP requests to trigger the abuse, which directly corresponds to the described unauthenticated access path. Its CVSS score of 9.1 indicates critical severity for confidentiality and integrity. However, the EPSS score of < 1 % indicates a very low probability that exploits are actively deployed, and the vulnerability is not listed in the CISA KEV catalog, which suggests it is not currently a widespread exploit threat.
OpenCVE Enrichment