Vulnerability in Oracle FLEXCUBE Universal Banking Component by Oracle
CVE-2019-2840

5.7MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
23 July 2019

Summary

A vulnerability exists in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications that could enable a low privileged attacker with network access via HTTP to compromise the system. Exploitation of this vulnerability requires human interaction from another individual. Successful attacks can lead to unauthorized access to critical data within the FLEXCUBE infrastructure, presenting significant security risks to financial institutions relying on this software. Affected versions range from 12.0.1 to 14.2.0.

Affected Version(s)

FLEXCUBE Universal Banking 12.0.1-12.0.3

FLEXCUBE Universal Banking 12.1.0-12.4.0

FLEXCUBE Universal Banking 14.0.0-14.2.0

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.