Impact
This vulnerability arises in the Oracle Data Integrator REST service. The flaw permits an unauthenticated attacker who can reach the application over HTTPS to compromise the instance. Once exploited, the attacker gains full control, effectively executing arbitrary code on the host. The weakness is captured by CWE‑284 (Improper Access Control) and CWE‑306 (Missing Authentication for Critical Function). The flaw influences confidentiality, integrity, and availability, and was classified with a CVSS 3.1 score of 9.8.
Affected Systems
Oracle Corporation's Oracle Data Integrator version 14.1.2.0.0, part of Oracle Fusion Middleware, is affected. No other products or versions were reported by the vendor.
Risk and Exploitability
The CVSS base score of 9.8 places it in the critical category. The EPSS score is less than 1%, indicating a very low current exploitation probability, and it is not listed in the CISA KEV catalog. Attackers need only network access to the HTTPS interface; no authentication or user interaction is required. If discovered, remote code execution or otherwise complete takeover could be achieved, making the vulnerability highly critical despite the low exploitation likelihood.
OpenCVE Enrichment