Executive brief
Oracle Forms is a development platform used to build database-driven enterprise applications. A flaw in the Forms Services component allows an unauthenticated attacker to gain unauthorized access to sensitive data and modify or delete critical information stored within deployed Forms applications. Exploitation requires network access and specific technical conditions, but does not require user interaction or authentication.
Technical details
The vulnerability exists in the Forms Services component (C/S, Charmode) of Oracle Forms within Oracle Fusion Middleware. It is a difficult-to-exploit flaw that requires an attacker to have network access via HTTP to reach the vulnerable service. An unauthenticated attacker can exploit this vulnerability to achieve unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to Forms-accessible data. The vulnerability affects Forms versions 12.2.1.19.0 and 14.1.2.0.0; patch availability and details from Oracle's advisory have not been publicly accessible at the time of analysis.
Affected products
- Oracle Forms 12.2.1.19.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed