Impact
A vulnerability in the Reports component of Oracle Banking Branch (versions 14.5.0.0.0 through 14.9.0.0.0) allows a low‑privileged attacker with network access over HTTP to trigger an exploit that requires human interaction from a user other than the attacker; successful exploitation results in full takeover of the application, compromising confidentiality, integrity, and availability.
Affected Systems
Oracle Banking Branch of Oracle Financial Services Applications is affected with the version range 14.5.0.0.0–14.9.0.0.0, as identified by the vendor.
Risk and Exploitability
The CVSS 8.0 score indicates severe impact, while the EPSS score of less than 1% shows a very low but still present exploitation probability; this vulnerability is not listed in CISA KEV. The attack requires a user‑initiated action, lowering the likelihood of automated attacks, but it still poses a significant risk, particularly if social engineering is used, and the mentioned scope change could allow impact on additional products.
OpenCVE Enrichment