Description
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-04-21
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Unauthorized access to critical data via unauthenticated HTTP requests
Action: Apply Patch
AI Analysis

Impact

The vulnerability in the Oracle Financial Services Analytical Applications Infrastructure allows an attacker with network access to its HTTP interface to bypass authentication controls and read all data exposed by the platform. This creates a confidentiality compromise, enabling the attacker to view sensitive financial information, while integrity and availability remain unchanged.

Affected Systems

Oracle Financial Services Analytical Applications Infrastructure versions 8.0.7.9, 8.0.8.7 and 8.1.2.5 are affected.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 indicates a high impact to confidentiality. EPSS data is not available and the vulnerability is not listed in CISA KEV. Attackers can exploit this flaw remotely over HTTP without authentication, meaning any network host able to reach the application can potentially extract data.

Generated by OpenCVE AI on April 22, 2026 at 06:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch released in the April 2026 CPU for Oracle Financial Services Analytical Applications Infrastructure
  • Limit access to the application’s HTTP interface to trusted networks only by configuring firewall or reverse‑proxy rules
  • Enable audit logging for the platform and monitor for anomalous authentication attempts

Generated by OpenCVE AI on April 22, 2026 at 06:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Apr 2026 07:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Access via HTTP in Oracle Financial Services Analytical Applications Infrastructure
Weaknesses CWE-285
CWE-287

Wed, 22 Apr 2026 02:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Access via HTTP in Oracle Financial Services Analytical Applications Infrastructure
Weaknesses CWE-285
CWE-287

Wed, 22 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle financial Services Analytical Applications Infrastructure
CPEs cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.7.9:*:*:*:*:*:*:*
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.8.7:*:*:*:*:*:*:*
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.2.5:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle financial Services Analytical Applications Infrastructure
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Financial Services Analytical Applications Infrastructure
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-04-21T20:35:36.885Z

Reserved: 2026-03-26T19:48:45.680Z

Link: CVE-2026-34310

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-21T21:16:36.510

Modified: 2026-04-21T21:16:36.510

Link: CVE-2026-34310

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T06:45:10Z

Weaknesses

No weakness.