Vulnerability in Oracle Banking Virtual Account Management by Oracle
CVE-2023-21908

6MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 April 2023

Summary

A vulnerability exists in the Oracle Banking Virtual Account Management product, affecting versions 14.5, 14.6, and 14.7. This security flaw allows an attacker with network access to compromise the system, requiring human interaction from a third party for successful exploitation. Attackers may gain unauthorized access to sensitive data, with the potential to manipulate or delete critical information. Additionally, this vulnerability may enable attackers to cause service disruption, leading to denial of service conditions within the Oracle Banking Virtual Account Management system. Organizations utilizing these versions are advised to implement security measures urgently.

Affected Version(s)

Banking Virtual Account Management 14.5

Banking Virtual Account Management 14.6

Banking Virtual Account Management 14.7

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.