PT-2021-2942 · Oracle · Oracle Flexcube Direct Banking

Waleed Ezz Eldin

·

Published

2021-04-22

·

Updated

2021-04-23

·

CVE-2021-2141

CVSS v2.0

2.1

Low

VectorAV:N/AC:H/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle FLEXCUBE Direct Banking versions 12.0.2 through 12.0.3
Description The issue exists due to insufficient input validation in the Pre Login component of Oracle FLEXCUBE Direct Banking. This allows a remote attacker to modify data or gain privileged access via network packets. The exploitation is difficult and requires human interaction from someone other than the attacker, resulting in potential unauthorized access to update, insert, or delete some accessible data.
Recommendations For versions 12.0.2 and 12.0.3, consider restricting network access via Oracle Net to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit privileged access to the Pre Login component to reduce the potential impact of the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02515
CVE-2021-2141

Affected Products

Oracle Flexcube Direct Banking