Impact
The vulnerability exists in Oracle Forms Services and Charmode, allowing an unauthenticated attacker who can reach the Forms application over HTTP to fully compromise the service. Successful exploitation results in full takeover, compromising confidentiality, integrity, and availability of the Forms environment as the CVSS vector indicates C:H/I:H/A:H with no authentication required. This represents a critical threat to any system running affected Oracle Forms versions.
Affected Systems
Oracle Corporation Oracle Forms is affected. The specific versions impacted are Oracle Forms 12.2.1.19.0 and 14.1.2.0.0. These versions are included in Oracle Fusion Middleware and are commonly deployed in enterprise environments.
Risk and Exploitability
The CVSS score of 9.8 classifies this flaw as Critical. The EPSS score is less than 1%, indicating a very low probability of current exploitation, though the vulnerability remains exploitable once Web access is available. Because the attack requires only network connectivity to the HTTP interface and no prior authentication, the scope is broad. The flaw is not listed in CISA's KEV catalog, but the impact warrants swift remediation.
OpenCVE Enrichment