Impact
A flaw in the Onboarding Batch Processes component of Oracle Banking Origination under Oracle Financial Services Applications permits a low‑privileged attacker with network access to an HTTP endpoint to compromise the system. If exploited successfully, an attacker can gain full control of Oracle Banking Origination, causing total loss of confidentiality, integrity, and availability of the application.
Affected Systems
Oracle Banking Origination versions 14.5.0.0.0 through 14.9.0.0.0 are affected. The vulnerability touches the Onboarding Batch Processes component and is reachable via standard HTTP traffic exposed to the network.
Risk and Exploitability
The vulnerability has a CVSS 3.1 base score of 7.5, indicating substantial impact. The EPSS score is below 1%, implying a very low probability of exploitation at this time. It is not listed in the CISA KEV catalog. The likely attack vector is a remote HTTP request from a low‑privilege user within the network, exploiting insufficient access controls to the batch process interface.
OpenCVE Enrichment