Executive brief
Oracle REST Data Services, a tool that enables developers to use HTTP(S) and REST to work with Oracle Databases, contains a security vulnerability in its core component. An unauthenticated attacker can exploit this flaw over the network to disrupt the service's availability. While this does not result in data theft, it can cause a partial denial of service, potentially slowing down or intermittently interrupting business applications that rely on these database web services.
Technical details
A vulnerability exists in the Core component of Oracle REST Data Services (ORDS) versions 24.2.0 through 26.1.0. The flaw is classified as easily exploitable and can be triggered by an unauthenticated attacker with network access via HTTPS. Successful exploitation allows the attacker to compromise the ORDS instance, specifically resulting in a partial denial of service (DoS) condition. The vulnerability has a CVSS 3.1 base score of 5.3, reflecting impacts solely on availability without affecting confidentiality or integrity. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.
Affected products
- Oracle REST Data Services 24.2.0-26.1.0
Timeline
- 2026-05-28: disclosed: Initial disclosure by Oracle and NVD publication.