Impact
The flaw exists in the Oracle SSL API component of Oracle Security Service. It allows an attacker who is on the network and can establish a TLS connection to the service to obtain unauthorized privilege. The exploitation requires a second human user to carry out a action on the attacker’s behalf, so the attack cannot be fully automated but can still elevate the attacker’s capabilities. Once exploited, the attacker can create, delete or modify access rights to critical data or gain complete access to all data that the service exposes.
Affected Systems
Oracle Corporation’s Oracle Security Service for Oracle Fusion Middleware is affected, specifically version 12.2.1.4.0. The vulnerability is documented in the Oracle SSL API component of the product. No other product or vendor versions are mentioned in the data.
Risk and Exploitability
The CVSS 3.1 base score of 6.4 indicates a medium severity that requires high attack complexity and low privilege. Attackers need network-level access through TLS and must persuade another user to perform a required action. The EPSS score of less than 1 % suggests that exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. If an attacker succeeds, they can gain unauthorized elevation of privileges and complete access to all data available through the Oracle Security Service, thereby compromising confidentiality and integrity of that data.
OpenCVE Enrichment