Impact
A flaw in the configuration component of Oracle Banking Origination lets an attacker who can reach the system through HTTP bypass permission checks and make unauthorized updates, inserts, or deletions of data, and read restricted information. The vulnerability is an access‑control bypass (CWE‑284) that can compromise the confidentiality and integrity of data accessed by the application. Successful exploitation also requires human interaction from a user other than the attacker, which reduces the likelihood of a purely automated attack.
Affected Systems
Oracle Banking Origination version 14.5.0.16.0 is affected. The description notes that exploitation of this flaw may also have implications for other products within the Oracle Financial Services Applications suite, but no other products are explicitly listed.
Risk and Exploitability
The CVSS base score of 6.1 classifies the flaw as moderate severity, and the EPSS score of less than 1 % indicates a low but non‑zero likelihood of exploitation. The attack vector is network-based via HTTP, requires no authentication, but also requires user interaction with a non‑attacker to complete the exploit. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widely known public exploitation.
OpenCVE Enrichment