Vulnerability in Oracle Financial Services Application: Banking Trade Finance
CVE-2022-21586

6.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 July 2022

Summary

A vulnerability exists in the Oracle Banking Trade Finance product of Oracle Financial Services Applications, specifically affecting version 14.5. This vulnerability enables a low-privileged attacker with network access via HTTP to exploit the system. Successful exploitation necessitates human interaction from another individual—thereby enhancing the complexity of the attack. Following a successful attack, the adversary could gain unauthorized capabilities to create, delete, or modify critical data within the Oracle Banking Trade Finance system, potentially affecting the integrity and confidentiality of this sensitive information.

Affected Version(s)

Banking Trade Finance 14.5

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.