Impact
A vulnerability in Oracle Forms allows a low‑privileged attacker who can reach the application over HTTP to gain unauthorized creation, deletion or modification of critical data, as well as unauthorized access to critical data and the ability to cause a partial denial of service. Successful exploitation requires human interaction from a user other than the attacker. The weakness is an access‑control misconfiguration that results in improper privilege management, enabling the attacker to bypass intended security boundaries.
Affected Systems
Affected applications include Oracle Forms 12.2.1.19.0 and 14.1.2.0.0, part of Oracle Corporation’s Oracle Fusion Middleware. These versions operate on the Forms Services, Client/Server, and Charmode components and are reachable over HTTP.
Risk and Exploitability
The CVSS v3.1 base score of 7.9 denotes moderate‑high severity, with confidentiality, integrity, and availability impacts. The EPSS score of less than 1% indicates a low probability of current exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the requirement for network access over HTTP and the need for a separate user to interact with the application mean that the attack vector is network‑based, with high exploitation complexity and low privileges. The scope change can affect other Oracle products, amplifying the potential damage to enterprise data.
OpenCVE Enrichment