Impact
The Web UI component of Oracle Financial Services Enterprise Case Management has an authentication bypass flaw (CWE‑287) that permits a low‑privileged attacker with network access to gain unauthorized access and compromise the system. The flaw is triggered by a specially crafted HTTP request sent to the web service and requires no user interaction. Successful exploitation compromises the confidentiality, integrity, and availability of the entire application, effectively allowing full takeover of the system.
Affected Systems
Oracle Financial Services Enterprise Case Management, versions 8.0.8.2 and 8.1.2.11, are affected by this vulnerability.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high severity outcome, while the EPSS score of less than 1% suggests a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation is likely carried out against the publicly reachable HTTP endpoint of the Web UI, requiring only low attack complexity and low attacker privileges; successful exploitation results in a full takeover of the application.
OpenCVE Enrichment