Impact
The Oracle FLEXCUBE Universal Banking product contains a vulnerability in the Relationship Pricing component that is easily exploitable by a low‑privileged attacker with network access. An attacker can compromise the application and gain unauthorized access to critical data, allowing them to read all data the application can access. The weakness reduces confidentiality, with no impact on integrity or availability, and maps to the improper access control weakness CWE‑284.
Affected Systems
Oracle Corporation’s Oracle FLEXCUBE Universal Banking is affected. Versions 14.0.0.0.0 through 14.8.0.0.0 are vulnerable. All deployments of these versions should be verified for a patch that addresses the Relationship Pricing component.
Risk and Exploitability
The vulnerability has a CVSS 3.1 base score of 6.5, indicating moderate severity. The EPSS score is below 1%, suggesting a low probability of exploitation at the time of analysis, and it is not listed in the CISA KEV catalog. The likely attack surface is the HTTP interface of the FLEXCUBE application; a remote attacker only needs network access and does not require user interaction, making the exploit straightforward for an adversary with low privileges.
OpenCVE Enrichment