Impact
This vulnerability allows a low‑privileged attacker who can reach the application over HTTP to compromise the Oracle Banking Corporate Lending Process Management system. The attack is described as difficult to exploit and requires human interaction from a user other than the attacker. Successful exploitation would grant the attacker full control over the application, compromising its confidentiality, integrity, and availability.
Affected Systems
Oracle Banking Corporate Lending Process Management, versions 14.5.0.0.0 through 14.9.0.0.0, part of Oracle Financial Services Applications.
Risk and Exploitability
Based on a CVSS score of 7.1, the vulnerability is considered high impact. The EPSS score is less than 1 %, indicating that the likelihood of exploitation is very low at present and the vulnerability is not listed in CISA KEV. The likely attack vector involves network access over HTTP, requiring a low‑privilege user with network connectivity, and necessitates user interaction to complete the exploit. The risk remains elevated because a successful attack would lead to a takeover of the system.
OpenCVE Enrichment