Impact
The vulnerability is an unauthenticated flaw that can be exploited over HTTP network access to the Oracle Banking Trade Finance Process Management application. The flaw arises from improper authorization controls (CWE‑284), cross‑site request forgery (CWE‑352), and open redirect vulnerabilities (CWE‑601). Successful exploitation allows an attacker to create, delete, or modify critical data and to gain unrestricted access to all data available through the system, resulting in significant confidentiality and integrity breaches. The impact also includes the ability to trigger a partial denial of service. Based on the description, it is inferred that the attack requires the presence of a user other than the attacker to interact with the system.
Affected Systems
Oracle Corporation’s Oracle Banking Trade Finance Process Management versions 14.6.0 through 14.8.0 (the Common component) are affected. Other related products may also be impacted if the vulnerability’s scope changes.
Risk and Exploitability
The CVSS base score of 9.6 classifies this issue as critical, with high damage potential to confidentiality, integrity, and availability. The EPSS score of less than 1% indicates a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Attackers must have HTTP network access and typically require a human user other than themselves to trigger the flaw, which suggests a low likelihood of widespread exploitation but a high impact if successful.
OpenCVE Enrichment