Impact
The flaw in Oracle Forms Services, specifically within the client/server and Charmode components, allows an attacker with low privileged network access to take complete control of the Forms service. By leveraging this, the attacker can compromise the confidentiality, integrity, and availability of the application. The weakness relates to improper authorization (CWE-284).
Affected Systems
Oracle Forms product from Oracle Corporation, affecting versions 12.2.1.19.0 and 14.1.2.0.0 which are part of the Oracle Fusion Middleware stack.
Risk and Exploitability
The vulnerability carries a CVSS v3.1 base score of 7.5, indicating high impact if exploited. The EPSS score is less than 1 %, suggesting a low probability of exploitation in the short term, and it is not listed in CISA’s KEV catalog. The attack vector, inferred from the description, requires only network access to the Forms HTTP service and does not require elevated privileges, making it potentially reachable from remote locations.
OpenCVE Enrichment