Impact
The vulnerability in Oracle Banking Trade Finance’s Infrastructure component allows a low‑privileged attacker who can reach the application over HTTP to create, delete, or modify critical data and to read any data the application exposes. This results in loss of confidentiality and integrity for all information managed by the system, effectively permitting the attacker to alter or erase business records.
Affected Systems
Oracle Banking Trade Finance versions 14.6.0 through 14.8.0 are impacted. The flaw resides in the Infrastructure component of the product bundle and affects all instances with those version numbers.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 signals high severity, while the EPSS score of less than 1 % indicates a currently low overall exploitation probability. The attack can be carried out remotely via HTTP from an account with modest privileges. Because the flaw enables direct data tampering and wide data access, any authenticated user with low rights could compromise the system if the application is reachable over the network. The issue is not listed in the CISA KEV catalog.
OpenCVE Enrichment