CRITICAL🇵🇱 Wersja polska

CVE-2025-53037

CVSS 9.8v3.1pub. 2025-10-21upd. 2025-10-23

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

🤖 AI Analysis
How it works

The vulnerability classified as CWE-306 (Missing Authentication for Critical Function) means that critical functions of the Platform component are accessible without any authentication. An attacker with network access to the system can send HTTP requests directly to protected resources, bypassing access control mechanisms. No credentials or user interaction are required, making the attack fully automated.

Impact

Successful exploitation of this vulnerability leads to complete takeover of the Oracle Financial Services Analytical Applications Infrastructure system, including breach of confidentiality, integrity, and availability of data. Attackers can gain unauthorized access to sensitive financial and analytical data, modify it, and cause service unavailability (DoS).

Mitigation & patch

Apply patches available from the vendor in accordance with references published as part of the Oracle Critical Patch Update from October 2025: https://www.oracle.com/security-alerts/cpuoct2025.html. Until the update is applied, it is recommended to restrict network access to the Platform component exclusively to trusted hosts at the firewall level and to monitor HTTP traffic directed to the system.

Who is affected

Oracle Financial Services Analytical Applications Infrastructure versions 8.0.7.9, 8.0.8.7, and 8.1.2.5 (component: Platform).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Oracle Financial Services Analytical Applications Infrastructure

    APP
    Oracle
    8.0.7.9.08.0.8.7.08.1.2.5.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassDoS
CWE
References

Related vulnerabilities

CVE-2022-22963CRITICAL9.8⚠ KEVPL ✓same product

RCE w Spring Cloud Function poprzez złośliwy SpEL routing-expression

CVE-2022-22965CRITICAL9.8⚠ KEVPL ✓same product

Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+

CVE-2021-26291CRITICAL9.1PL ✓same product

Apache Maven: podążanie za niezaufanymi repozytoriami HTTP (MitM)

CVE-2020-10683CRITICAL9.8PL ✓same product

XXE w bibliotece dom4j — domyślne zezwolenie na zewnętrzne encje XML

CVE-2020-9546CRITICAL9.8PL ✓same product

RCE poprzez niebezpieczną deserializację w FasterXML jackson-databind