Impact
The vulnerability is an authorization bypass in Oracle Forms that allows an unauthenticated attacker with network access via HTTP to gain unauthorized access to critical data or all data accessible through Oracle Forms. It is an access control flaw (CWE-284) that can expose confidential information and potentially affect other products that rely on Forms services.
Affected Systems
Oracle Forms versions 12.2.1.19.0 and 14.1.2.0.0 are affected. The flaw resides in the Forms Services, client/server and Charmode components of Oracle Fusion Middleware.
Risk and Exploitability
The CVSS 3.1 base score of 8.6 indicates high severity, with a low exploitation probability (EPSS < 1%) and it is not listed in the CISA KEV catalog. The likely attack vector is over the network via standard HTTP traffic; the flaw can be exploited without authentication, making it easily exploitable to compromise the Forms deployment and any downstream applications that use its data.
OpenCVE Enrichment