Executive brief
Oracle Web Services Manager is a component of Oracle Fusion Middleware that manages security for web services. An unauthenticated attacker with network access can exploit a difficult-to-exploit vulnerability in the Web Services Security component to gain complete control of the Web Services Manager system, affecting the confidentiality, integrity, and availability of services and data.
Technical details
This vulnerability in Oracle Web Services Manager's Web Services Security component allows an unauthenticated attacker with network access via HTTPS to compromise the system. The vulnerability is difficult to exploit but can result in complete takeover when successfully exploited. No specific authentication or user interaction is required. The attack is network-reachable and does not require special access levels. Affected versions are 12.2.1.4.0 and 14.1.2.0.0. Oracle has published security patches to address this issue.
Affected products
- Oracle Web Services Manager 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-08-18: disclosed