Oracle Financial Services Revenue Management and Billing Chatbot Vulnerability Allowing Data Compromise and Partial Denial-of-Service

Vulnerability

A vulnerability has been identified in the Oracle Financial Services Revenue Management and Billing product, specifically in the Chatbot component. This issue affects versions 5.1.0.0.0, 6.1.0.0.0, and 7.0.0.0.0. The vulnerability is difficult to exploit but allows a high-privileged attacker with network access via HTTP to compromise the application. Exploitation requires human interaction from a person other than the attacker. Successful attacks can lead to unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to all accessible data within the application. Additionally, the vulnerability allows for a partial denial-of-service condition.

Impact

Exploitation of this vulnerability could result in unauthorized access to critical data, complete access to all Oracle Financial Services Revenue Management and Billing accessible data, and an unauthorized ability to cause a partial denial-of-service condition on the application.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
5.6
exploitability
4.5
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.