Vulnerability in Oracle Financial Services Revenue Management and Billing by Oracle
CVE-2025-50074

4.9MEDIUM

What is CVE-2025-50074?

A vulnerability has been identified in the Oracle Financial Services Revenue Management and Billing product, specifically within the Security Management System component. This flaw allows a high-privileged attacker with network access via HTTP to potentially compromise the billing system. If exploited, attackers could gain unauthorized access to critical data, leading to significant data exposure from all accessible records within the Oracle Financial Services application. It is essential for organizations using this product to take necessary precautions to safeguard their data.

Affected Version(s)

Oracle Financial Services Revenue Management and Billing 2.9.0.0.0 <= 7.2.0.0.0

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.