Executive brief
Oracle Forms is a web application development and deployment framework used to build enterprise business applications. A critical vulnerability in the Forms Services component allows a privileged attacker with network access to completely take over the system, potentially compromising confidentiality, integrity, and availability of the application and related systems.
Technical details
The vulnerability exists in Oracle Forms product (Fusion Middleware), specifically in the Forms Services component (C/S and Charmode modes). It is easily exploitable via HTTP by an attacker with high privileges. The vulnerability has a scope change, meaning successful exploitation can impact additional products beyond Oracle Forms itself. Affected versions include 12.2.1.19.0 and 14.1.2.0.0. An attacker can achieve complete system takeover (compromise of confidentiality, integrity, and availability). Patch availability is not specified in the provided advisory.
Affected products
- Oracle Forms 12.2.1.19.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed