Oracle REST Data Services
cpe:2.3:a:oracle:rest_data_services:*:*:*:*:*:*:*
- >= 24.2.0, <= 26.1.0
A vulnerability has been identified in Oracle REST Data Services, specifically in the Core component, affecting versions 24.2.0 through 26.1.0. This vulnerability allows a low-privileged attacker with network access via HTTPS to compromise the application. While the issue resides within Oracle REST Data Services, successful exploitation could significantly impact additional products, leading to a scope change. The vulnerability allows for the takeover of Oracle REST Data Services.
Exploitation of this vulnerability can lead to a complete takeover of the Oracle REST Data Services instance.
Users are advised to apply the latest patches available through the Oracle Critical Security Patch Update program. Instructions for applying these patches can be found in the Oracle REST Data Services patch availability document on My Oracle Support.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.