Executive brief
A vulnerability exists in the Oracle platform used by financial institutions for data analysis and infrastructure management. An attacker with basic user credentials could exploit this flaw to gain unauthorized access to sensitive financial data or modify critical records. Such an incident could lead to significant data breaches, regulatory non-compliance, and loss of data integrity within the organization's analytical environment.
Technical details
This vulnerability is classified as an improper access control issue (CWE-284) within the Platform component of Oracle Financial Services Analytical Applications Infrastructure. It is exploitable by a low-privileged attacker with network access via HTTP, though Oracle notes the attack complexity is high, suggesting specific conditions or timing are required for success. If successfully exploited, the attacker can achieve unauthorized read, create, delete, or modification access to all data accessible by the infrastructure. The vulnerability affects versions 8.0.7.9, 8.0.8.7, and 8.1.2.5, and users are advised to refer to the Oracle Critical Patch Update for remediation.
Affected products
- Oracle Financial Services Analytical Applications Infrastructure 8.0.7.9, 8.0.8.7, 8.1.2.5
Timeline
- 2026-04-21: disclosed: Initial disclosure by Oracle
- 2026-04-21: advisory: NVD published the CVE record