Impact
The vulnerability resides in the Forms Services component of Oracle Fusion Middleware. It allows an unauthenticated attacker with HTTP network access to execute arbitrary code or fully compromise the Oracle Forms instance. The weakness is an authorization bypass and missing authentication (CWE‑287, CWE‑306) that provides confidentiality, integrity, and availability damage as reflected in the CVSS score of 9.8.
Affected Systems
Affected deployments are Oracle Forms 12.2.1.19.0 and 14.1.2.0.0. These versions are still in use in many enterprises that rely on Oracle Fusion Middleware for application development and execution.
Risk and Exploitability
The CVSS base score of 9.8 denotes critical severity, while the EPSS indicates a very low probability of exploitation at present (<1%). Nevertheless the vulnerability remains listed as high risk. Attackers can reach the vulnerable instance over public or internal HTTP without authentication, making the exploitation path straightforward. Once executed, the attacker gains full control of Oracle Forms, jeopardising all its services.
OpenCVE Enrichment