Impact
The vulnerability is an improper access control flaw in Oracle Forms Services, Client/Server, and Charmode components. A threat actor with high privileges who can reach Oracle Forms over HTTP can create, delete, or alter any data exposed through the forms interface and can also trigger application hangs or repeated crashes, resulting in a full denial of service. The CVSS v3.1 base score of 6.5 reflects moderate‑to‑high severity with impacts on data integrity and application availability.
Affected Systems
Affected products are Oracle Forms 12.2.1.19.0 and 14.1.2.0.0, which are deployed as part of Oracle Fusion Middleware. The flaw applies to any instance that includes the Forms Services, Client/Server, or Charmode components, regardless of the underlying operating system.
Risk and Exploitability
The EPSS score is less than 1 %, indicating a low current exploitation probability, and the vulnerability is not in the CISA KEV catalog. Nevertheless, the CVSS score indicates that if exploited, an attacker could modify or delete critical data and disrupt service availability. The likely attack vector is a network‑based attack over HTTP that requires the attacker to have or obtain high‑privilege credentials to bypass access controls within Oracle Forms.
OpenCVE Enrichment