Impact
This vulnerability in Oracle Forms allows an attacker with network access to a compromised HTTP interface to elevate privileges and take full control of the application. The flaw results in complete loss of confidentiality, integrity and availability for the affected instance. The disclosed CVSS vector indicates a network attack that can be performed with low effort and high privilege impact, resulting in a 9.1 base score.
Affected Systems
Oracle Forms product of Oracle Fusion Middleware, versions 12.2.1.19.0 and 14.1.2.0.0 are affected. The vulnerability exists in the Forms Services, Client/Server, Charmode components. These versions are currently supported under Oracle’s release schedule.
Risk and Exploitability
The CVSS score of 9.1 marks this as a critical issue, and although the EPSS score is presently less than 1%, the fact that it is exploitable over HTTP makes it a priority for defense. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog, but the potential for a full takeover means it could be a high‑profile target should an attacker discover it. Based on the description, the likely attack vector is a network‑based HTTP request that bypasses normal authentication checks, allowing an attacker to obtain high‑privilege control of the Forms instance.
OpenCVE Enrichment