Description
Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: Oracle SSL API). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via TLS to compromise Oracle Security Service. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Security Service accessible data as well as unauthorized access to critical data or complete access to all Oracle Security Service accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw exists in the Oracle SSL API component of Oracle Security Service. It allows an attacker who is on the network and can establish a TLS connection to the service to obtain unauthorized privilege. The exploitation requires a second human user to carry out a action on the attacker’s behalf, so the attack cannot be fully automated but can still elevate the attacker’s capabilities. Once exploited, the attacker can create, delete or modify access rights to critical data or gain complete access to all data that the service exposes.

Affected Systems

Oracle Corporation’s Oracle Security Service for Oracle Fusion Middleware is affected, specifically version 12.2.1.4.0. The vulnerability is documented in the Oracle SSL API component of the product. No other product or vendor versions are mentioned in the data.

Risk and Exploitability

The CVSS 3.1 base score of 6.4 indicates a medium severity that requires high attack complexity and low privilege. Attackers need network-level access through TLS and must persuade another user to perform a required action. The EPSS score of less than 1 % suggests that exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. If an attacker succeeds, they can gain unauthorized elevation of privileges and complete access to all data available through the Oracle Security Service, thereby compromising confidentiality and integrity of that data.

Generated by OpenCVE AI on August 4, 2026 at 01:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch that addresses the Oracle SSL API issue for version 12.2.1.4.0
  • Limit or disable TLS‑based administrative interfaces that are not essential to business operations
  • Enforce multi‑factor authentication for all administrative access and restrict such access to authorized personnel
  • Apply strict access controls so that only the minimum necessary privileges are granted
  • Monitor authentication and audit logs for suspicious privilege changes or abnormal user activity

Generated by OpenCVE AI on August 4, 2026 at 01:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Network-Based TLS Exploit Enables Unauthorized Access in Oracle Security Service

Thu, 30 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Network-Based TLS Exploit Enables Unauthorized Access in Oracle Security Service

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Authorization and Cross‑Site Request Forgery Vulnerability in Oracle Security Service via TLS

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Authorization and Cross‑Site Request Forgery Vulnerability in Oracle Security Service via TLS

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-290
CWE-352
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: Oracle SSL API). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via TLS to compromise Oracle Security Service. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Security Service accessible data as well as unauthorized access to critical data or complete access to all Oracle Security Service accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle security Service
CPEs cpe:2.3:a:oracle:security_service:12.2.1.4.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle security Service
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Security Service
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:34:50.397Z

Reserved: 2026-07-08T15:52:20.741Z

Link: CVE-2026-61217

cve-icon Vulnrichment

Updated: 2026-07-22T18:34:47.022Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:30:04Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-290

    Authentication Bypass by Spoofing

  • CWE-352

    Cross-Site Request Forgery (CSRF)