Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Web Services Manager. Successful attacks of this vulnerability can result in takeover of Oracle Web Services Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspuaug2026.html |
|
History
Sat, 22 Aug 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated HTTPS Authentication Bypass in Oracle Web Services Manager |
Sat, 22 Aug 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated HTTPS Exploit Permitting Full Takeover of Oracle Web Services Manager | |
| Weaknesses | CWE-287 |
Sat, 22 Aug 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-306 | |
| Metrics |
ssvc
|
Fri, 21 Aug 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated HTTPS Exploit Permitting Full Takeover of Oracle Web Services Manager | |
| Weaknesses | CWE-287 |
Thu, 20 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:oracle:web_services_manager:14.1.2.1.0:*:*:*:*:*:*:* |
Thu, 20 Aug 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated HTTPS Access Allows Complete Compromise of Oracle Web Services Manager | |
| Weaknesses | CWE-284 CWE-287 |
Wed, 19 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated HTTPS Access Allows Complete Compromise of Oracle Web Services Manager | |
| Weaknesses | CWE-284 CWE-287 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Web Services Manager. Successful attacks of this vulnerability can result in takeover of Oracle Web Services Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle web Services Manager |
|
| CPEs | cpe:2.3:a:oracle:web_services_manager:12.2.1.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:web_services_manager:14.1.2.0.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Oracle
Oracle web Services Manager |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-08-18T21:02:32.353Z
Updated: 2026-08-22T02:40:15.205Z
Reserved: 2026-08-04T22:06:34.606Z
Link: CVE-2026-70924
Updated: 2026-08-22T02:40:10.334Z
Status : Modified
Published: 2026-08-18T21:17:50.280
Modified: 2026-08-22T03:16:22.963
Link: CVE-2026-70924
No data.