Impact
A flaw in the Web Services Agent component of Oracle Web Services Manager allows an unauthenticated attacker with network access to the HTTP interface to compromise the application. Successful exploitation can result in unauthorized access to critical data and the ability to insert, update, or delete data managed by the service, thereby creating confidentiality and integrity violations. The weakness is a type of improper access control that permits users to bypass authentication entirely.
Affected Systems
Oracle Web Services Manager versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The product is part of Oracle Fusion Middleware and maintains a Web Services Agent component that receives HTTP traffic. Users should verify that these builds are in use before proceeding with any remediation steps.
Risk and Exploitability
The CVSS v3.1 base score of 8.2 indicates a high severity rating. The EPSS score of less than 1% suggests that, as of this analysis, the likelihood of exploitation in the wild is low, though the vulnerability is still potentially dangerous. It is not listed in CISA's KEV catalog. The most probable attack vector is an unauthenticated HTTP request from an external network; exploitation does not require privileged access or user interaction. The impact is limited to confidentiality and integrity, with no availability effects reported.
OpenCVE Enrichment