Impact
A flaw in Oracle Forms allows an unauthenticated attacker with network connectivity via HTTP to bypass authentication and fully compromise the application, causing confidentiality, integrity, and availability violations. The vulnerability can produce a complete takeover of the Forms service and is classified as a Remote Code Execution exploit.
Affected Systems
Oracle Corporation’s Oracle Forms product, specifically version 12.2.1.19.0 and 14.1.2.0.0, is affected. Users running these releases should verify if they remain within the supported patch lifecycle.
Risk and Exploitability
The CVSS v3.1 Base Score of 10.0 reflects a critical attack impact, and the EPSS score of less than 1% indicates that widespread exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog, though the known attack vector is an unauthenticated HTTP request. Successful exploitation would shift the scope to involve additional products and could lead to a compromise of the entire application environment.
OpenCVE Enrichment