Description
Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Trade Finance accessible data as well as unauthorized access to critical data or complete access to all Oracle Banking Trade Finance accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the Oracle Banking Trade Finance product, affecting the Infrastructure component. An attacker with low privileges and network access through HTTP can create, delete, or modify access to critical data. Successful exploitation results in unauthorized creation, deletion, or modification of data and potential complete access to all data accessible by the banking trade system. The weakness results in elevated confidentiality and integrity impacts.

Affected Systems

Oracle Corporation’s Oracle Banking Trade Finance product, versions 14.6.0 through 14.8.0, is affected. The vulnerability is present in the Infrastructure component of the Oracle Financial Services Applications suite.

Risk and Exploitability

The CVSS v3.1 base score of 8.1 indicates high severity with confidentiality and integrity impacts. The EPSS score of less than 1% suggests a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over the network via HTTP, requiring only low privileges. While exploitation requires an attacker to be able to reach the application, the impact is significant if achieved. Organizations should treat this as a high‑priority risk due to the potential for significant data loss or corruption.

Generated by OpenCVE AI on August 4, 2026 at 01:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch or upgrade to a version older than 14.6.0 or newer than 14.8.0 once Oracle issues an update.
  • Restrict HTTP access to the Oracle Banking Trade Finance service to trusted networks only and implement strict firewall rules.
  • Enforce least‑privilege access control policies and audit user permissions regularly to ensure that only authorized accounts can modify critical data.
  • Monitor authentication and access logs for unusual activity and set up alerts for failed authentication attempts or unauthorized data modification attempts.

Generated by OpenCVE AI on August 4, 2026 at 01:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Data Modification in Oracle Banking Trade Finance

Thu, 30 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Data Modification in Oracle Banking Trade Finance

Mon, 27 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Access Control Flaw Enabling Unauthorized Data Modification in Oracle Banking Trade Finance
Weaknesses CWE-287

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Access Control Flaw Enabling Unauthorized Data Modification in Oracle Banking Trade Finance
Weaknesses CWE-284
CWE-287

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Trade Finance accessible data as well as unauthorized access to critical data or complete access to all Oracle Banking Trade Finance accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle banking Trade Finance
CPEs cpe:2.3:a:oracle:banking_trade_finance:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle banking Trade Finance
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Banking Trade Finance
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T13:57:31.523Z

Reserved: 2026-07-08T15:51:55.613Z

Link: CVE-2026-61102

cve-icon Vulnrichment

Updated: 2026-07-24T13:57:18.013Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-07-21T22:18:41.360

Modified: 2026-07-24T15:19:03.160

Link: CVE-2026-61102

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:00:12Z

Weaknesses