Oracle · Oracle Banking Virtual Account Management · CVE-2023-21903
**Name of the Vulnerable Software and Affected Versions**
Oracle Banking Virtual Account Management versions 14.5 through 14.7
**Description**
The issue is related to insufficient input validation in the OBVAM Internal Tfr Domain component of Oracle Banking Virtual Account Management, part of Oracle Financial Services Applications. This can allow a remote attacker to cause a denial of service or gain read, modify, add, or delete access to data. Successful attacks require human interaction from a person other than the attacker and can result in unauthorized access to critical data, update, insert, or delete access to some data, and the ability to cause a partial denial of service.
**Recommendations**
For versions 14.5 through 14.7, consider restricting access to the OBVAM Internal Tfr Domain component until a patch is available. As a temporary workaround, limit network access via HTTP to minimize the risk of exploitation. Ensure that only high-privileged attackers with proper authorization have access to the system to reduce the impact of a potential attack. At the moment, there is no information about a newer version that contains a fix for this vulnerability.