Oracle FLEXCUBE Universal Banking Vulnerability in Financial Services Applications
CVE-2019-2839

5.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
23 July 2019

Summary

A vulnerability exists in the Oracle FLEXCUBE Universal Banking component that may allow a low-privileged attacker with network access via HTTP to gain unauthorized access to sensitive data. This flaw affects supported versions ranging from 12.1.0 to 14.2.0, enabling successful exploitation to potentially allow full access to critical banking data. The vulnerability highlights the importance of securing financial applications to prevent data breaches.

Affected Version(s)

FLEXCUBE Universal Banking 12.1.0-12.4.0

FLEXCUBE Universal Banking 14.0.0-14.2.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.