Impact
The vulnerability exists in the Oracle Banking Trade Finance product, affecting the Infrastructure component. An attacker with low privileges and network access through HTTP can create, delete, or modify access to critical data. Successful exploitation results in unauthorized creation, deletion, or modification of data and potential complete access to all data accessible by the banking trade system. The weakness results in elevated confidentiality and integrity impacts.
Affected Systems
Oracle Corporation’s Oracle Banking Trade Finance product, versions 14.6.0 through 14.8.0, is affected. The vulnerability is present in the Infrastructure component of the Oracle Financial Services Applications suite.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 indicates high severity with confidentiality and integrity impacts. The EPSS score of less than 1% suggests a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over the network via HTTP, requiring only low privileges. While exploitation requires an attacker to be able to reach the application, the impact is significant if achieved. Organizations should treat this as a high‑priority risk due to the potential for significant data loss or corruption.
OpenCVE Enrichment