Impact
The vulnerability resides in the Console / Repository Explorer component of Oracle Data Integrator and permits an attacker who can reach the service over HTTP to bypass all authentication controls. By exploiting this weakness the attacker gains full control of the Data Integrator instance, compromising confidentiality, integrity, and availability of the application and any data it processes. The issue is rooted in the failure to verify user credentials (CWE‑287) and the absence of authentication entirely for the console interface (CWE‑306).
Affected Systems
Oracle Data Integrator versions 12.2.1.4.0 and 14.1.2.0.0 are confirmed vulnerable. No other versions were identified as affected in the advisory.
Risk and Exploitability
The CVSS v3.1 base score of 9.8 reflects the severe impact of a full takeover. Although the EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, the attack vector requires only network access to HTTP and no special privileges, making it readily exploitable in a suitable environment. The high severity, combined with the direct bypass of authentication, demands urgent remediation.
OpenCVE Enrichment