Vulnerability in Oracle FLEXCUBE Universal Banking Affects Financial Services Applications
CVE-2022-21579

6.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 July 2022

Summary

A vulnerability in the Oracle FLEXCUBE Universal Banking product allows a low privileged attacker with network access via HTTP to compromise the system. The attack requires human interaction from another person, which complicates exploitation efforts. If successful, this vulnerability can lead to unauthorized creation, deletion, or modification of critical data, granting the attacker access to sensitive information within Oracle FLEXCUBE. Affected versions include 12.1 to 12.4 and 14.0 to 14.5, making it crucial for users to apply necessary security measures to safeguard their data against potential threats.

Affected Version(s)

FLEXCUBE Universal Banking 12.1-12.4

FLEXCUBE Universal Banking 14.0-14.3

FLEXCUBE Universal Banking 14.5

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.