Input Validation Flaw in Oracle FLEXCUBE Private Banking Component
CVE-2017-3476
7.1HIGH
Summary
A vulnerability exists in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications that allows attackers with low privileges and network access through HTTP to exploit the system. This easily exploitable flaw can lead to unauthorized access to sensitive customer information and critical financial data. It may also enable attackers to modify, insert, or delete data within the system, raising significant concerns regarding the integrity and confidentiality of the information held in Oracle FLEXCUBE Private Banking.
Affected Version(s)
FLEXCUBE Private Banking 2.0.0
FLEXCUBE Private Banking 2.0.1
FLEXCUBE Private Banking 2.2.0.1
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved