Vulnerability in Oracle's FLEXCUBE Direct Banking Component
CVE-2017-10181
6.8MEDIUM
Summary
The vulnerability in Oracle's FLEXCUBE Direct Banking component occurs in the Forgot Password functionality, which enables low-privileged attackers with network access to exploit the system. Successful exploitation could lead to unauthorized access to sensitive data, as well as the ability to cause service interruptions. Attackers require human interaction to exploit this vulnerability, making it a unique risk to users of Oracle FLEXCUBE Direct Banking version 12.0.2 and 12.0.3.
Affected Version(s)
FLEXCUBE Direct Banking 12.0.2
FLEXCUBE Direct Banking 12.0.3
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved