Unauthenticated Access Vulnerability in Oracle Web Services Manager by Oracle
CVE-2022-21497

8.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 April 2022

Summary

The vulnerability in Oracle Web Services Manager, part of Oracle Fusion Middleware, poses a significant risk by allowing unauthenticated attackers with network access via HTTP to compromise the service. Exploitation requires user interaction from a victim to execute a successful attack. If exploited, this vulnerability may lead to unauthorized creation, deletion, or modification of critical data, compromising the confidentiality and integrity of the underlying data accessible through the Oracle Web Services Manager.

Affected Version(s)

Web Services Manager 12.2.1.3.0

Web Services Manager 12.2.1.4.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.