Impact
Oracle Forms by Oracle Fusion Middleware has a vulnerability in the Forms Services component that can be exploited by an attacker who has network access over HTTP. The flaw is easily exploitable and allows the attacker to gain high privileges, which can lead to a full takeover of the Oracle Forms application. Successful exploitation would compromise confidentiality, integrity, and availability of the affected system, and the impact can extend to other dependent products, as the scope is changed.
Affected Systems
The affected product is Oracle Forms from Oracle Corporation. Versions 12.2.1.19.0 and 14.1.2.0.0 are impacted. The vulnerability is specific to the Forms Services, C/S, Charmode component of Oracle Fusion Middleware.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity, but the EPSS score of less than 1% suggests that, at the time of this analysis, the likelihood of real‑world exploitation is low. The vulnerability is not listed in CISA KEV. The likely attack vector involves sending a crafted HTTP request to the Form Services endpoint, exploiting the code path that fails to enforce proper access control and allows the attacker to elevate privileges and execute arbitrary code.
OpenCVE Enrichment