Impact
The vulnerability in the Oracle Financial Services Analytical Applications Infrastructure allows an attacker with network access to its HTTP interface to bypass authentication controls and read all data exposed by the platform. This creates a confidentiality compromise, enabling the attacker to view sensitive financial information, while integrity and availability remain unchanged.
Affected Systems
Oracle Financial Services Analytical Applications Infrastructure versions 8.0.7.9, 8.0.8.7 and 8.1.2.5 are affected.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates a high impact to confidentiality. EPSS data is not available and the vulnerability is not listed in CISA KEV. Attackers can exploit this flaw remotely over HTTP without authentication, meaning any network host able to reach the application can potentially extract data.
OpenCVE Enrichment