Impact
The reported issue allows an unauthenticated attacker with access to a physical communication segment attached to the hardware where the Oracle Banking Corporate Lending product runs to create, delete, or modify critical data. The attacker can gain complete or partial access to all data exposed by the application, effectively compromising confidentiality and integrity.
Affected Systems
Oracle Corporation’s Oracle Banking Corporate Lending, versions 14.5.0.0.0 through 14.9.0.0.0, are affected. The vulnerability may also affect other components within the Oracle Financial Services Applications suite due to a scope change in the attack.
Risk and Exploitability
This vulnerability has a CVSS 3.1 base score of 8.0, indicating high severity. The EPSS score is below 1%, suggesting a low probability of exploitation, and it is not listed in CISA KEV. The attack vector is inferred to be an adjacent network (physical communication segment), with high attack complexity and no authentication required. Successful exploitation would grant the attacker the ability to alter or delete critical data and could potentially expose all data handled by the product.
OpenCVE Enrichment