Impact
The vulnerability in Oracle Web Services Manager permits an unauthenticated attacker who can reach the service over HTTPS to compromise the application. This flaw is an authentication bypass and a missing authentication weakness (CWE-306). Successful exploitation can lead to a full takeover, compromising confidentiality, integrity, and availability of the system.
Affected Systems
The affected product is Oracle Web Services Manager from Oracle Corporation. Versions 12.2.1.4.0, 14.1.2.0.0, and 14.1.2.1.0 are vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 indicates high severity. The EPSS score is < 1%, indicating a very low but nonzero probability of exploitation. The vulnerability can be exploited over the network via HTTPS with no user interaction and requires no privileges. The issue is not yet listed in the CISA KEV catalog, which does not necessarily reduce risk. Given the ease of access and potential for full compromise, the risk remains significant.
OpenCVE Enrichment