Description
Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Trade Finance accessible data as well as unauthorized access to critical data or complete access to all Oracle Banking Trade Finance accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Banking Trade Finance’s Infrastructure component allows a low‑privileged attacker who can reach the application over HTTP to create, delete, or modify critical data and to read any data the application exposes. This results in loss of confidentiality and integrity for all information managed by the system, effectively permitting the attacker to alter or erase business records.

Affected Systems

Oracle Banking Trade Finance versions 14.6.0 through 14.8.0 are impacted. The flaw resides in the Infrastructure component of the product bundle and affects all instances with those version numbers.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 signals high severity, while the EPSS score of less than 1 % indicates a currently low overall exploitation probability. The attack can be carried out remotely via HTTP from an account with modest privileges. Because the flaw enables direct data tampering and wide data access, any authenticated user with low rights could compromise the system if the application is reachable over the network. The issue is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 4, 2026 at 01:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch for Banking Trade Finance 14.8.0 or later as detailed in the CPU July 2026 advisory.
  • Restrict HTTP access to the Banking Trade Finance service to trusted IP ranges or via a VPN tunnel.
  • Enforce strict role‑based access controls and audit data‑access permissions to ensure only authorized users can create, delete, or modify critical data.

Generated by OpenCVE AI on August 4, 2026 at 01:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Data Tampering in Oracle Banking Trade Finance

Sun, 02 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Data Tampering in Oracle Banking Trade Finance

Sat, 01 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Access via HTTP in Oracle Banking Trade Finance

Sun, 26 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Access via HTTP in Oracle Banking Trade Finance

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Trade Finance accessible data as well as unauthorized access to critical data or complete access to all Oracle Banking Trade Finance accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle banking Trade Finance
CPEs cpe:2.3:a:oracle:banking_trade_finance:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle banking Trade Finance
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Banking Trade Finance
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:22:28.901Z

Reserved: 2026-07-08T15:51:55.613Z

Link: CVE-2026-61105

cve-icon Vulnrichment

Updated: 2026-07-23T19:22:24.151Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-07-21T22:18:41.690

Modified: 2026-07-23T20:17:15.790

Link: CVE-2026-61105

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:00:12Z

Weaknesses