Executive brief
Oracle Banking Corporate Lending is a financial services platform used by banks to manage corporate lending operations and customer credit data. An attacker with physical access to the network infrastructure where the system is deployed could exploit a difficult-to-exploit vulnerability to read, modify, or delete sensitive lending data and customer information, potentially impacting confidentiality and integrity of critical banking records.
Technical details
This vulnerability exists in the Core component of Oracle Banking Corporate Lending and affects versions 14.5.0.0.0 through 14.9.0.0.0. It is a physical-access vulnerability requiring an unauthenticated attacker with network connectivity to the hardware's local communication segment; the difficulty of exploitation and lack of remote network access requirements indicate specialized hardware access is necessary. Successful exploitation allows unauthorized creation, deletion, or modification of critical lending data and customer information accessible by the system. The vulnerability has scope change implications, suggesting impacts may extend to dependent systems. No patch availability information is currently available from the provided advisory materials.
Affected products
- Oracle Banking Corporate Lending 14.5.0.0.0-14.9.0.0.0
Timeline
- 2026-09-15: disclosed