CVE-2026-83334
largeUnauthenticated Data Disclosure and DoS in Oracle Web Services Manager (Fusion Middleware)
CVE-2026-83334 is a difficult-to-exploit flaw in the Web Services Security component of Oracle Web Services Manager (OWSM), part of Oracle Fusion Middleware. An unauthenticated remote attacker who has network access to the product's SOAP interfaces can send crafted requests that compromise OWSM, resulting in unauthorized read access to critical data or all OWSM-accessible data, plus the ability to cause a hang or frequently repeatable crash (complete denial of service). The vulnerability affects OWSM versions 12.2.1.4.0 and 14.1.2.0.0 and carries a CVSS 3.1 base score of 7.4 (high), driven by confidentiality and availability impacts with no integrity impact. The high attack complexity means exploitation is not trivial, and successful attacks require no privileges or user interaction. There is no known public proof of concept, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been reported; a fix is available through Oracle's Critical Patch Update program.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83334 to all Oracle Web Services Manager installations running 12.2.1.4.0 or 14.1.2.0.0, prioritizing any OWSM/SOAP endpoints reachable from untrusted networks. Restrict or proxy SOAP and WSM policy endpoints at the network perimeter so they are not directly internet-facing. Monitor OWSM-managed Web services for repeated crashes, hangs, or anomalous unauthenticated SOAP request patterns that could indicate exploitation attempts.
| Oracle Web Services Manager (Oracle Fusion Middleware, component: Web Services Security) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Web Services Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Web Services Manager accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Web Services Manager. CVSS 3.1 Base Score 7.4 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.