Impact
This vulnerability resides in Oracle Forms Services, C/S, Charmode, and permits an unauthenticated attacker with network access via HTTP to read confidential data. The flaw does not provide remote code execution or privilege escalation, but it allows the disclosure of a subset of Forms‑accessible data. The weakness is an improper access control that permits unauthenticated read access to protected resources.
Affected Systems
Oracle Forms delivered by Oracle Corporation, specifically versions 12.2.1.19.0 and 14.1.2.0.0, are impacted. Users running these builds, whether on‑premises or as part of Oracle Fusion Middleware, are exposed to the described data‑exposure risk.
Risk and Exploitability
The CVSS 3.1 base score of 5.3 indicates a moderate confidentiality impact with low attack complexity and no required privileges. The EPSS score of less than 1% reflects a very low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based, unauthenticated, with no user interaction, meaning that any system exposing the Forms service to the internet or an internal network without proper authentication can be compromised. The overall risk level is moderate but should not be ignored, particularly if sensitive data is exposed via Forms.
OpenCVE Enrichment