Impact
The defect allows an attacker without authentication, who can reach the Oracle Web Services Manager over the network, to send a specially crafted SOAP request that triggers the vulnerability. A successful exploitation results in unauthorized access to protected data as well as a full takeover of all data the manager controls, and the attacker can also cause the service to hang or repeatedly crash, generating a denial of service.
Affected Systems
Oracle Web Services Manager versions 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware. These releases are affected and must be checked for patching.
Risk and Exploitability
The CVSS 3.1 base score of 7.4 marks the issue as high severity. The EPSS score of less than 1 percent indicates that, as of the latest data, the likelihood of exploitation is very low. The vulnerability is not listed in the CISA KEV catalogue. The attack vector is inferred to be network based, through a SOAP interface; authentication is not required, making the process simple for an impacted user. Successful exploitation would give the attacker the same access as the Web Services Manager service, enabling data exfiltration or service disruption.
OpenCVE Enrichment