Impact
A vulnerability in the Reports component of Oracle Banking Branch allows a low‑privileged attacker with network access via HTTP to compromise the application, but the attack requires user interaction from a separate person. The issue can lead to full application takeover, affecting confidentiality, integrity, and availability.
Affected Systems
Oracle Banking Branch, a component of Oracle Financial Services Applications for banking operations, is affected. Versions from 14.5.0.0.0 through 14.9.0.0.0 contain the Reports module that is vulnerable. Sysadmins should verify whether their deployments run any of these versions.
Risk and Exploitability
The CVSS v3.1 Base Score is 7.1, indicating a high impact when exploitation is successful. The EPSS score is less than 1%, suggesting that the probability of exploitation in the wild is low at present, and the vulnerability is not listed in CISA's KEV catalog. The attack requires network connectivity to the HTTP endpoint of a While the exploitation conditions are stringent, the potential to compromise the entire application warrants prompt attention.
OpenCVE Enrichment