Executive brief
Oracle Banking Corporate Lending Process Management is a component of Oracle Financial Services Applications used for managing corporate lending workflows. A vulnerability in the Base component allows a low-privileged attacker with network access to compromise the system, potentially leading to complete takeover of the lending platform. Exploitation requires user interaction, but successful attacks can result in unauthorized access to sensitive banking data and operational disruption.
Technical details
This is a difficult-to-exploit privilege escalation or access control vulnerability in the Base component of Oracle Banking Corporate Lending Process Management. The vulnerability is reachable via HTTP from a network-adjacent attacker with low privileges, but requires human interaction (likely social engineering or click-based attack) from a person other than the attacker. When successfully exploited, it allows complete compromise of the application with impacts to confidentiality, integrity, and availability. The vulnerability affects versions 14.5.0.0.0 through 14.9.0.0.0. Patch availability is not specified in the available advisory text.
Affected products
- Oracle Banking Corporate Lending Process Management 14.5.0.0.0-14.9.0.0.0
Timeline
- 2026-09-15: disclosed