Exploitable Vulnerability in Oracle FLEXCUBE Direct Banking Component
CVE-2019-2549
6.1MEDIUM
Summary
An exploitable vulnerability exists in the Logoff Page component of Oracle FLEXCUBE Direct Banking, allowing unauthenticated attackers with network access to compromise the application. The vulnerability enables unauthorized updates, inserts, or deletions of accessible data, along with read access to sensitive information, contingent upon human interaction. Despite its specific targeting of Oracle FLEXCUBE, successful exploitation may impact other connected financial applications significantly.
Affected Version(s)
FLEXCUBE Direct Banking 12.0.2
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved