PT-2025-42936 · Oracle · Oracle Financial Services Analytical Applications Infrastructure

Published

2025-10-21

·

Updated

2025-10-21

·

CVE-2025-53037

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Financial Services Analytical Applications Infrastructure versions 8.0.7.9 through 8.1.2.5
Description An easily exploitable issue exists in the Oracle Financial Services Analytical Applications Infrastructure component of Oracle Financial Services Applications. An unauthenticated attacker with network access via HTTP can compromise the system, potentially leading to a complete takeover of the infrastructure. The issue allows for remote code execution.
Recommendations Oracle Financial Services Analytical Applications Infrastructure version 8.0.7.9 should be updated. Oracle Financial Services Analytical Applications Infrastructure version 8.0.8.7 should be updated. Oracle Financial Services Analytical Applications Infrastructure version 8.1.2.5 should be updated.

Fix

RCE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13381
CVE-2025-53037

Affected Products

Oracle Financial Services Analytical Applications Infrastructure