Executive brief
Oracle Forms is a component of Oracle Fusion Middleware used to build and deploy enterprise applications with web-based interfaces. An unauthenticated attacker with network access can exploit this vulnerability to read sensitive data that should be restricted, potentially exposing customer information or business-critical details without proper authentication or authorization controls.
Technical details
This is an information disclosure vulnerability in Oracle Forms Services (C/S and Charmode components) that allows unauthenticated attackers to bypass access controls. The vulnerability is easily exploitable via HTTP over the network and requires no user interaction or special privileges. Successful exploitation results in unauthorized read access to a subset of Oracle Forms data, compromising confidentiality. The vulnerability affects Forms versions 12.2.1.19.0 and 14.1.2.0.0 in Oracle Fusion Middleware.
Affected products
- Oracle Forms 12.2.1.19.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed