Vulnerability in Oracle Banking Virtual Account Management by Oracle
CVE-2023-21905

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 April 2023

Summary

A vulnerability exists in the Routing Hub component of Oracle Banking Virtual Account Management that allows an attacker with high privileges and network access via HTTP to exploit weaknesses within the system. This vulnerability necessitates human interaction from a user other than the attacker, which could lead to unauthorized creation, modification, or deletion of critical data. Successful exploitation would grant the attacker access to sensitive information across all Oracle Banking Virtual Account Management accessible data, posing a significant risk to the confidentiality and integrity of financial information.

Affected Version(s)

Banking Virtual Account Management 14.5

Banking Virtual Account Management 14.6

Banking Virtual Account Management 14.7

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.