Vulnerability in Oracle FLEXCUBE Private Banking Affects Financial Services Applications
CVE-2017-10010
What is CVE-2017-10010?
A vulnerability exists in the Oracle FLEXCUBE Private Banking component that allows a low-privileged attacker with network access via HTTP to compromise the system. This flaw enables unauthorized actions that include the ability to update, insert, or delete data, as well as read sensitive information. Notably, these successful attacks require human interaction from an external user, which may increase the risk of exploitation in scenarios where user awareness is low. Various versions of the product are affected and thus require prompt mitigation measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FLEXCUBE Private Banking 2.0.0
FLEXCUBE Private Banking 2.0.1
FLEXCUBE Private Banking 2.2.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved