Vulnerability in Oracle FLEXCUBE Universal Banking by Oracle
CVE-2022-21544
7.1HIGH
Summary
A vulnerability exists in the Oracle FLEXCUBE Universal Banking product that enables an attacker with low privileges and HTTP network access to exploit the system. Successful exploitation requires human interaction, making it particularly insidious in nature. This can lead to a complete takeover of the banking application, thereby compromising confidentiality, integrity, and availability of sensitive financial data. Organizations using affected versions must prioritize patching to mitigate the risks associated with this vulnerability.
Affected Version(s)
FLEXCUBE Universal Banking 12.1-12.4
FLEXCUBE Universal Banking 14.0-14.3
FLEXCUBE Universal Banking 14.5
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved