Impact
Oracle Forms services in Oracle Fusion Middleware expose an unauthenticated HTTP interface that can be abused to execute arbitrary code on the host. The vulnerability is caused by improper access control (CWE-284), allowing an attacker to run code with the privileges of the Forms process. Successful exploitation would result in loss of confidentiality, integrity, and availability for the affected deployment, potentially impacting other Oracle components that rely on Forms Services, C/S, or Charmode.
Affected Systems
Oracle Forms versions 12.2.1.19.0 and 14.1.2.0.0, part of Oracle Fusion Middleware. The flaw applies to the Forms Services, C/S, and Charmode components, and may also affect additional Oracle products that depend on these services.
Risk and Exploitability
The CVSS score of 9.0 (AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H) marks this flaw as critical. The EPSS score of less than 1% indicates a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless the attack requires only unauthenticated HTTP access, and the high complexity coupled with a scope change means that a compromised Forms instance could grant an attacker full control over the affected system and possibly other Oracle components.
OpenCVE Enrichment