Vulnerability in Oracle FLEXCUBE Direct Banking Affecting Financial Services Applications
CVE-2017-3495
4.7MEDIUM
Summary
A security vulnerability exists in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Applications, specifically impacting versions 12.0.2 and 12.0.3. This exploit allows an unauthenticated attacker with HTTP network access to compromise the application. Although successful attacks may require human interaction from a user who is not the attacker, the vulnerability poses risks that can lead to unauthorized read access to sensitive data within Oracle FLEXCUBE. Due diligence is necessary to mitigate impacts, as these attacks can extend to affect additional products.
Affected Version(s)
FLEXCUBE Direct Banking 12.0.2
FLEXCUBE Direct Banking 12.0.3
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved