Impact
A vulnerability exists in the Oracle SOA Suite B2B Engine component of Oracle Fusion Middleware. Based on the description, it is inferred that a remote attacker who can reach the system over HTTP—even with low‑privileged credentials—can exploit the flaw to compromise the entire Oracle SOA Suite instance, gaining full control and causing loss of confidentiality, integrity, and availability. The CVSS 3.1 base score of 8.8 highlights significant impact and low effort required to exploit.
Affected Systems
Oracle SOA Suite from Oracle Corporation, specifically versions 12.2.1.4.0 and 14.1.2.0.0. The affected component is the B2B Engine part of Oracle Fusion Middleware.
Risk and Exploitability
The flaw can be triggered remotely through HTTP by an attacker with low privileges. The CVSS base score of 8.8 indicates high severity. EPSS score is not available, so the exploitation probability cannot be determined. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker does not need elevated credentials or a graphical interface to exploit the flaw. If successful, the attacker would gain full control over the application.
OpenCVE Enrichment