Executive brief
Oracle Web Services Manager is a security and management component of Oracle Fusion Middleware that controls access to web services. A vulnerability in its Web Services Security component allows an unauthenticated attacker with network access to bypass authentication and either steal sensitive data or crash the service, resulting in potential data exposure and operational disruption.
Technical details
This is an authentication bypass vulnerability in Oracle Web Services Manager's Web Services Security component, accessible via SOAP protocol. The vulnerability is difficult to exploit but requires no authentication, no user interaction, and only network access to the vulnerable service. Successful exploitation allows an attacker to either exfiltrate critical data stored in Oracle Web Services Manager or cause a denial-of-service condition through repeated crashes or hangs. Affected versions are 12.2.1.4.0 and 14.1.2.0.0. Oracle has issued patches as part of their September 2026 security advisory.
Affected products
- Oracle Web Services Manager 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed