Attackers can execute arbitrary code without authentication if Oracle's Identity or Web Services Managers are exposed to the Web.