Impact
This vulnerability resides in the Forms Services component of Oracle Forms within Oracle Fusion Middleware, specifically affecting versions 12.2.1.19.0 and 14.1.2.0.0. An unauthenticated attacker with HTTP network access can exploit a difficult‑to‑exploit flaw that grants the ability to create, delete, or modify critical data accessed through Oracle Forms. The impact is a compromise of confidentiality and integrity of all data exposed by the affected instances, as indicated by the CVSS 3.1 Base Score of 7.4.
Affected Systems
Oracle Forms, a product of Oracle Corporation distributed as part of Oracle Fusion Middleware, contains the vulnerable Forms Services, Client/Server, Charmode subsystem. Versions 12.2.1.19.0 and 14.1.2.0.0 are affected and all applications hosted on these instances are at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.4, signaling a moderate‑to‑high risk level because of the potential for significant confidentiality and integrity loss. However, the EPSS score is less than 1 %, suggesting that public exploitation cases are unlikely at present. The CVE is not listed in the CISA KEV catalog, further indicating low exploitation probability. Attackers would need to send unauthenticated HTTP requests to the Forms service; once the condition is met, they could write arbitrary data, creating, deleting, or modifying sensitive records.
OpenCVE Enrichment