Unauthenticated Access Vulnerability in Oracle FLEXCUBE Private Banking Component
CVE-2017-3471
4.7MEDIUM
What is CVE-2017-3471?
A vulnerability has been identified in the Oracle FLEXCUBE Private Banking component within Oracle Financial Services Applications, impacting versions 12.0.0 and 12.1.0. This vulnerability permits an unauthenticated attacker with network access to exploit the system via HTTP. While the attack requires human interaction from a user other than the attacker, it poses a risk of unauthorized data manipulation, including updates, inserts, or deletions of accessible data within the FLEXCUBE Private Banking environment. This weakness could lead to significant ramifications for interconnected products and services.
Affected Version(s)
FLEXCUBE Private Banking 12.0.0
FLEXCUBE Private Banking 12.1.0