Vulnerability in Oracle Web Services Manager of Oracle Fusion Middleware
CVE-2023-21862
8.1HIGH
Summary
A vulnerability exists in the Oracle Web Services Manager component of Oracle Fusion Middleware, specifically in its XML Security component. This issue allows an unauthenticated attacker with network access over HTTP to potentially compromise the service. An attacker must persuade a user to interact with a malicious link to exploit this flaw, leading to unauthorized creation, deletion, or modification of critical data within Oracle Web Services Manager. Consequently, this could result in unauthorized access to sensitive information, affecting the confidentiality and integrity of the data managed by the service.
Affected Version(s)
Web Services Manager 12.2.1.4.0
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved