Lucene search

K
cve[email protected]CVE-2022-21562
HistoryJul 19, 2022 - 10:15 p.m.

CVE-2022-21562

2022-07-1922:15:12
web.nvd.nist.gov
36
3
oracle
soa suite
vulnerability
oracle fusion middleware
fabric layer
cve-2022-21562
security
http
cvss 3.1

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

7.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

33.1%

Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Fabric Layer). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle SOA Suite accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).

Affected configurations

Vulners
NVD
Node
oraclesoa_suiteRange12.2.1.3.0
OR
oraclesoa_suiteRange12.2.1.4.0
VendorProductVersionCPE
oraclesoa_suite*cpe:2.3:a:oracle:soa_suite:*:*:*:*:*:*:*:*
oraclesoa_suite*cpe:2.3:a:oracle:soa_suite:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "SOA Suite",
    "vendor": "Oracle Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "12.2.1.3.0"
      },
      {
        "status": "affected",
        "version": "12.2.1.4.0"
      }
    ]
  }
]

Social References

More

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

7.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

33.1%

Related for CVE-2022-21562