Vulnerability in Oracle FLEXCUBE Private Banking Component of Oracle Financial Services Applications
CVE-2017-3479
5.4MEDIUM
Summary
A vulnerability exists in the Oracle FLEXCUBE Private Banking component, which can be exploited by a low-privileged attacker with HTTP network access. The exploitation of this flaw can lead to unauthorized modifications of the system, including the ability to update, insert, or delete sensitive data. Additionally, it poses a risk of causing a partial denial of service, impacting the availability of the Oracle FLEXCUBE Private Banking application. Supported versions vulnerable to this issue include 2.0.0, 2.0.1, 2.2.0.1, and 12.0.1.
Affected Version(s)
FLEXCUBE Private Banking 2.0.0
FLEXCUBE Private Banking 2.0.1
FLEXCUBE Private Banking 2.2.0.1
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved