Impact
The vulnerability resides in the Forms Services, C/S, Charmode component of Oracle Forms within Oracle Fusion Middleware. An unauthenticated attacker who can reach the HTTP endpoint can exploit the flaw, potentially taking full control of the application. Because the flaw can be triggered without credentials, the attacker can compromise confidentiality, integrity, and availability, effectively achieving remote code execution or takeover of Oracle Forms.
Affected Systems
Affected are Oracle Forms 12.2.1.19.0 and 14.1.2.0.0, both supported versions of Oracle Fusion Middleware. Systems running either of these builds without the published fix should be considered at risk. Administration should review deployment inventories to identify any instances of these versions.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 indicates high severity, and the EPSS score of less than 1% shows a low current exploitation probability. The flaw is not listed in CISA’s KEV catalog. Attackers only need network-level HTTP access to the Forms service, no user interaction or privileged credentials. Given the high impact and the straightforward attack vector, the risk remains high and remediation should be prioritized.
OpenCVE Enrichment