SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-0699

Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.2 and 12.0.3 allows remote attackers to affect confidentiality and integrity via vectors related to the Login sub-component.

CRITICAL 9.1EPSS 2.77%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.77%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.2 and 12.0.3 allows remote attackers to affect confidentiality and integrity via vectors related to the Login sub-component.

CVSS 3.0
9.1 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS
2.77% probability · 86th percentile
CISA KEV
Not listed
Affected
oracle/flexcube direct banking
Source
secalert_us@oracle.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.