Exploitable Vulnerability in Oracle FLEXCUBE Universal Banking
CVE-2019-2793

3.5LOW

Key Information:

Vendor
Oracle
Vendor
CVE Published:
23 July 2019

Summary

This vulnerability in Oracle FLEXCUBE Universal Banking allows a low-privileged attacker to exploit the system through HTTP access. Although the attacker requires human interaction from an uninvolved party, successful exploitation could lead to a partial denial of service, disrupting the availability of the application. This vulnerability affects several versions, including those from 12.0.1 to 14.2.0, highlighting the importance of security measures and updates for users of Oracle's financial services software.

Affected Version(s)

FLEXCUBE Universal Banking 12.0.1-12.0.3

FLEXCUBE Universal Banking 12.1.0-12.4.0

FLEXCUBE Universal Banking 14.0.0-14.2.0

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.