Description
Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base). Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Banking Corporate Lending Process Management. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Takeover of Oracle Banking Corporate Lending Process Management
Action: Immediate Patch
AI Analysis

Impact

This vulnerability allows a low‑privileged attacker who can reach the application over HTTP to compromise the Oracle Banking Corporate Lending Process Management system. The attack is described as difficult to exploit and requires human interaction from a user other than the attacker. Successful exploitation would grant the attacker full control over the application, compromising its confidentiality, integrity, and availability.

Affected Systems

Oracle Banking Corporate Lending Process Management, versions 14.5.0.0.0 through 14.9.0.0.0, part of Oracle Financial Services Applications.

Risk and Exploitability

Based on a CVSS score of 7.1, the vulnerability is considered high impact. The EPSS score is less than 1 %, indicating that the likelihood of exploitation is very low at present and the vulnerability is not listed in CISA KEV. The likely attack vector involves network access over HTTP, requiring a low‑privilege user with network connectivity, and necessitates user interaction to complete the exploit. The risk remains elevated because a successful attack would lead to a takeover of the system.

Generated by OpenCVE AI on September 16, 2026 at 21:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade to a version beyond 14.9.0.0.0
  • Restrict HTTP access to the Banking Corporate Lending Process Management system to authorized IP ranges and enforce strict network segmentation
  • Enable comprehensive logging and monitoring of HTTP requests to detect suspicious activity and enforce user‑interaction checks

Generated by OpenCVE AI on September 16, 2026 at 21:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit Allows Takeover of Oracle Banking Corporate Lending Process Management
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base). Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Banking Corporate Lending Process Management. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle banking Corporate Lending Process Management
CPEs cpe:2.3:a:oracle:banking_corporate_lending_process_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle banking Corporate Lending Process Management
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Banking Corporate Lending Process Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T20:04:21.008Z

Reserved: 2026-08-31T15:40:57.346Z

Link: CVE-2026-83206

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:32.203

Modified: 2026-09-16T19:36:43.087

Link: CVE-2026-83206

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T21:45:06Z

Weaknesses