Impact
A flaw in the Oracle Fusion Middleware Control product allows a low‑privilege attacker who can reach the system over HTTP to gain unauthorized ability to update, insert, delete, or read data that is normally protected by the control interface. The vulnerability requires interaction from a legitimate user other than the attacker, preventing full autonomous exploitation. The impact is limited to confidentiality and integrity of the data exposed through the control service, and does not affect availability. The stated scope change indicates that a successful compromise of the control component could also influence other Oracle Fusion Middleware products that are managed or accessed through this interface.
Affected Systems
Oracle Corporation’s Oracle Fusion Middleware Control is affected. The versions that contain the flaw are 12.2.1.4.0 and 14.1.2.0.0. The vulnerability is present in the Framework component of these releases.
Risk and Exploitability
The CVSS vector AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N gives the vulnerability a moderate score of 5.4, reflecting modest confidentiality and integrity consequences. The EPSS score of less than 1 % indicates a low probability of current exploitation. Because the flaw is not listed in the CISA KEV catalog and requires a human assistant, widespread exploitation is unlikely at this time. The attack path is over the network via HTTP, exploiting the control interface; however, the scope change means that success could extend the damage to other middleware components that rely on the same control layer.
OpenCVE Enrichment