Impact
A flaw in Oracle Forms allows an unauthenticated user who can reach the application over HTTP to bypass authentication and obtain full control of the Forms instance. The vulnerability resides in the Forms Services processor and permits the attacker to take over the system, potentially executing arbitrary code and exfiltrating data. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates a high impact on confidentiality, integrity and availability. The fault lies in the Forms Services, client/server (C/S) and Charmode components of Oracle Fusion Middleware. Only the two versions listed—12.2.1.19.0 and 14.1.2.0.0—are impacted. An attacker who can reach the Forms server through the network can exploit the flaw by sending crafted HTTP requests, with no prior authentication or user interaction required. With a CVSS base of 9.8, the vulnerability is classified as critical; however, the EPSS score of < 1 % indicates that known exploitation is rare, and the issue is not cataloged in CISA’s KEV list. Nevertheless, the ease of exploitation and the requirement of only network connectivity make the risk significant for any organization exposing Forms to the internet or internal networks that are not sufficiently segmented.
Affected Systems
Oracle Corporation’s Oracle Forms product, versions 12.2.1.19.0 and 14.1.2.0.0, is affected. The flaw involves the Forms Services, client/server (C/S), and Charmode components of Oracle Fusion Middleware, which are deployed in organizational environments that expose HTTP access to the Forms application.
Risk and Exploitability
With a CVSS base of 9.8, the vulnerability is classified as critical; however, the EPSS score of < 1 % indicates that known exploitation is rare, and the issue is not cataloged in CISA’s KEV list. Nevertheless, the ease of exploitation and the requirement of only network connectivity make the risk significant for any organization exposing Forms to the internet or internal networks that are not sufficiently segmented.
OpenCVE Enrichment