Vulnerability in Oracle Financial Services Revenue Management and Billing
CVE-2025-50075

6.5MEDIUM

What is CVE-2025-50075?

A security vulnerability exists in Oracle Financial Services Revenue Management and Billing, specifically within the Security Management System component. The affected versions can be leveraged by attackers with low privileges and network access via HTTP, enabling them to compromise the system. Successful exploitation may grant unauthorized access to sensitive data or full control over all data accessible within the platform. Organizations using the affected versions should review their security measures and apply necessary patches.

Affected Version(s)

Oracle Financial Services Revenue Management and Billing 2.9.0.0.0 <= 7.2.0.0.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.