PT-2019-1309 · Oracle · Oracle Flexcube Direct Banking

Published

2019-01-16

·

Updated

2020-08-24

·

CVE-2019-2549

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle FLEXCUBE Direct Banking version 12.0.2
Description The issue is related to insufficient access control in the Oracle FLEXCUBE Direct Banking component, specifically in the Logoff Page. This can be exploited by a remote attacker to gain unauthorized access to protected information using the HTTP protocol. Successful attacks require human interaction and can result in unauthorized access to some data, including update, insert, or delete access, as well as read access to a subset of the data.
Recommendations For version 12.0.2, consider restricting access to the Logoff Page until a patch is available to prevent unauthorized access. As a temporary workaround, limit the use of the HTTP protocol for sensitive operations to minimize the risk of exploitation.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00580
CVE-2019-2549

Affected Products

Oracle Flexcube Direct Banking