Vulnerability in Oracle Banking Trade Finance Product by Oracle
CVE-2022-21585

6.7MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 July 2022

Summary

A vulnerability in the Oracle Banking Trade Finance product allows low privileged attackers with HTTP network access to manipulate critical data. The attack requires human interaction, significantly limiting the exploitability. If successful, it can lead to unauthorized creation, deletion, or modification of sensitive data and may partially disrupt the availability of the service. This highlights the importance of applying timely security patches and maintaining secure configurations.

Affected Version(s)

Banking Trade Finance 14.5

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.