Impact
This vulnerability is an authentication bypass flaw in Oracle Forms Services that allows an unauthenticated attacker with TCP network access to create, delete, or modify critical data or to gain full access to all data accessible via Oracle Forms. The weakness aligns with CWE-287 and CWE-306, indicating failures in proper authentication enforcement and allowing anonymous access. The impact is high for confidentiality and integrity but does not affect availability.
Affected Systems
The affected product is Oracle Forms, part of Oracle Fusion Middleware. Versions 12.2.1.19.0 and 14.1.2.0.0 are specifically vulnerable. Administrators should verify whether their installations run these exact versions and prioritize remediation accordingly.
Risk and Exploitability
The CVSS 3.1 base score is 9.1, with an attack vector of network and low complexity, meaning the flaw is easily exploitable. The EPSS score is <1%, indicating a low but non-zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a network TCP connection to the Forms Services endpoint, allowing an attacker to trigger the flaw without credentials.
OpenCVE Enrichment