Vulnerability in Oracle Banking Virtual Account Management by Oracle
CVE-2023-21904

5.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 April 2023

Summary

A vulnerability exists in Oracle Banking Virtual Account Management that allows a high-privileged attacker with network access to exploit the system. This issue requires human interaction from a user other than the attacker, making it somewhat challenging to initiate. Successful exploitation can lead to unauthorized access to sensitive data and give attackers the ability to perform updates, inserts, or deletions of accessible data, potentially resulting in partial denial of service. Organizations using supported versions 14.5, 14.6, and 14.7 should prioritize applying available patches to mitigate these risks.

Affected Version(s)

Banking Virtual Account Management 14.5

Banking Virtual Account Management 14.6

Banking Virtual Account Management 14.7

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.