Impact
The vulnerability resides in the Web Services Security component of Oracle Web Services Manager, allowing attackers with network access via HTTP to create, delete or modify data that the product manages. The impact is a loss of confidentiality and integrity, as attackers can gain unauthorized access or alter critical data. The weakness is a form of access control failure, permitting low‑privileged users to elevate their permissions inadvertently.
Affected Systems
Oracle Web Services Manager versions 12.2.1.4.0, 14.1.2.0.0, and 14.1.2.1.0 are affected. These versions run as part of Oracle Fusion Middleware and may be deployed on various operating systems; the issue is identified by the three corresponding CPE strings specified in the CVE data.
Risk and Exploitability
The CVSS score of 9.6 indicates a critical severity. The attack vector is via network HTTP traffic and only low privilege, making the vulnerability readily exploitable. The entry is not listed in CISA KEV and its EPSS score is <1%, indicating a very low but non‑zero exploitation probability, but the high CVSS and the obvious network attack surface suggest a significant risk to systems that expose Web Services Manager to untrusted networks. Successful exploitation would give attackers unauthorized control over data held by the product and potentially affect other products that share the same data or configuration settings.
OpenCVE Enrichment