Impact
The vulnerability resides in Oracle Forms, component of Oracle Fusion Middleware, allowing an unauthenticated attacker with network access via HTTP to bypass authentication and fully compromise the Forms application. Successful exploitation results in complete control over the application, threatening confidentiality, integrity, and availability. The weakness involves improper authentication handling (CWE-287) and missing authorization checks (CWE-306).
Affected Systems
Oracle Corporation’s Oracle Forms versions 12.2.1.19.0 and 14.1.2.0.0 are affected.
Risk and Exploitability
With a CVSS v3.1 base score of 9.8, this flaw is critical, and an EPSS score of below 1% indicates a low probability of widespread exploitation. It is not listed in CISA’s KEV catalog. The attack vector is a network-based, unauthenticated HTTP request to the Forms service, making it straightforward to target in environments where the service is exposed.
OpenCVE Enrichment