Description
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Web Services Manager. Successful attacks of this vulnerability can result in takeover of Oracle Web Services Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Web Services Manager permits an unauthenticated attacker who can reach the service over HTTPS to compromise the application. This flaw is an authentication bypass and a missing authentication weakness (CWE-306). Successful exploitation can lead to a full takeover, compromising confidentiality, integrity, and availability of the system.

Affected Systems

The affected product is Oracle Web Services Manager from Oracle Corporation. Versions 12.2.1.4.0, 14.1.2.0.0, and 14.1.2.1.0 are vulnerable.

Risk and Exploitability

The CVSS v3.1 base score of 8.1 indicates high severity. The EPSS score is < 1%, indicating a very low but nonzero probability of exploitation. The vulnerability can be exploited over the network via HTTPS with no user interaction and requires no privileges. The issue is not yet listed in the CISA KEV catalog, which does not necessarily reduce risk. Given the ease of access and potential for full compromise, the risk remains significant.

Generated by OpenCVE AI on August 22, 2026 at 06:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patches for Oracle Web Services Manager versions 12.2.1.4.0, 14.1.2.0.0, and 14.1.2.1.0 as detailed in the Oracle security advisory.
  • Deploy firewall rules or VPN restrictions to limit direct internet access to the Web Services Manager console, permitting connections only from trusted internal hosts.
  • Enforce strict authentication on the HTTPS endpoints, such as client certificate validation or multifactor authentication, to prevent unauthenticated access.

Generated by OpenCVE AI on August 22, 2026 at 06:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Authentication Bypass in Oracle Web Services Manager

Sat, 22 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Exploit Permitting Full Takeover of Oracle Web Services Manager
Weaknesses CWE-287

Sat, 22 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Exploit Permitting Full Takeover of Oracle Web Services Manager
Weaknesses CWE-287

Thu, 20 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:oracle:web_services_manager:14.1.2.1.0:*:*:*:*:*:*:*

Thu, 20 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Access Allows Complete Compromise of Oracle Web Services Manager
Weaknesses CWE-284
CWE-287

Wed, 19 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Access Allows Complete Compromise of Oracle Web Services Manager
Weaknesses CWE-284
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Web Services Manager. Successful attacks of this vulnerability can result in takeover of Oracle Web Services Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle web Services Manager
CPEs cpe:2.3:a:oracle:web_services_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:web_services_manager:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle web Services Manager
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Web Services Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-22T02:40:15.205Z

Reserved: 2026-08-04T22:06:34.606Z

Link: CVE-2026-70924

cve-icon Vulnrichment

Updated: 2026-08-22T02:40:10.334Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:17:50.280

Modified: 2026-08-22T03:16:22.963

Link: CVE-2026-70924

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T07:00:07Z

Weaknesses