Description
Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports). Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Branch. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Banking Branch. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Application Compromise
Action: Patch Now
AI Analysis

Impact

A vulnerability in the Reports component of Oracle Banking Branch allows a low‑privileged attacker with network access via HTTP to compromise the application, but the attack requires user interaction from a separate person. The issue can lead to full application takeover, affecting confidentiality, integrity, and availability.

Affected Systems

Oracle Banking Branch, a component of Oracle Financial Services Applications for banking operations, is affected. Versions from 14.5.0.0.0 through 14.9.0.0.0 contain the Reports module that is vulnerable. Sysadmins should verify whether their deployments run any of these versions.

Risk and Exploitability

The CVSS v3.1 Base Score is 7.1, indicating a high impact when exploitation is successful. The EPSS score is less than 1%, suggesting that the probability of exploitation in the wild is low at present, and the vulnerability is not listed in CISA's KEV catalog. The attack requires network connectivity to the HTTP endpoint of a While the exploitation conditions are stringent, the potential to compromise the entire application warrants prompt attention.

Generated by OpenCVE AI on September 17, 2026 at 04:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor-released patch or upgrade to a version that removes the vulnerable Reports component.
  • Restrict HTTP access to the Reports module to trusted internal users, disabling anonymous and low‑privileged accounts.
  • Enable logging and monitor for abnormal report‑generation requests, and enforce strict role–based access controls.

Generated by OpenCVE AI on September 17, 2026 at 04:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Title Low Privileged Network Attacker Requires Human Interaction to Compromise Oracle Banking Branch via HTTP
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports). Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Branch. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Banking Branch. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle banking Branch
CPEs cpe:2.3:a:oracle:banking_branch:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle banking Branch
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Banking Branch
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:20:58.245Z

Reserved: 2026-08-31T15:40:57.338Z

Link: CVE-2026-83080

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:17.723

Modified: 2026-09-16T19:36:43.087

Link: CVE-2026-83080

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T04:15:11Z

Weaknesses