Impact
The vulnerability arises in Oracle Forms Services, where unauthenticated HTTP requests can be processed without proper authentication checks. Because the system allows certain privileged operations to be triggered by any network client, a remote attacker can compromise the Forms service, leading to loss of confidentiality, integrity, and availability. The weakness corresponds to improper authentication (CWE-287) and missing authentication enforcement (CWE-306).
Affected Systems
The flaw affects Oracle Corporation’s Oracle Forms product, a component of Oracle Fusion Middleware. Supported affected versions are 12.2.1.19.0 and 14.1.2.0.0. These versions run on systems that expose the Forms service through HTTP, typically accessed by client applications over a network. An unauthenticated attacker with network access can compromise the Forms service.
Risk and Exploitability
The CVSS v3.1 base score of 9.8 indicates critical severity, and the EPSS score of less than 1% suggests low immediate exploitation probability in the wild. However, because the attack requires only unauthenticated HTTP access, an attacker can attempt exploitation on any exposed instance. The vulnerability is not yet listed in CISA’s KEV catalog, so there is no confirmed widespread exploitation, but the combination of high impact and simple access means it should be treated as a high risk. Attackers would send crafted HTTP requests to the Forms endpoint to invoke privileged operations, bypassing all authentication checks.
OpenCVE Enrichment