Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Web UI).  Supported versions that are affected are 8.0.8.1, 8.1.2.7 and  8.1.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Behavior Detection Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Behavior Detection Platform accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Behavior Detection Platform accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://www.oracle.com/security-alerts/cpujan2025.html | 
                     | 
            
History
                    Thu, 13 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-352 | 
Wed, 12 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Tue, 21 Jan 2025 21:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Web UI). Supported versions that are affected are 8.0.8.1, 8.1.2.7 and 8.1.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Behavior Detection Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Behavior Detection Platform accessible data as well as unauthorized read access to a subset of Oracle Financial Services Behavior Detection Platform accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). | |
| First Time appeared | 
        
        Oracle
         Oracle financial Services Behavior Detection Platform  | 
|
| CPEs | cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.0.8.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.2.7:*:*:*:*:*:*:* cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.2.8:*:*:*:*:*:*:*  | 
|
| Vendors & Products | 
        
        Oracle
         Oracle financial Services Behavior Detection Platform  | 
|
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: oracle
Published: 2025-01-21T20:53:16.198Z
Updated: 2025-03-13T14:21:51.251Z
Reserved: 2024-12-24T23:18:54.775Z
Link: CVE-2025-21550
Updated: 2025-02-12T20:33:36.496Z
Status : Analyzed
Published: 2025-01-21T21:15:21.510
Modified: 2025-06-23T15:25:05.683
Link: CVE-2025-21550
No data.