CVE-2017-3236
CVE-2017-3236 is a medium-severity vulnerability in Oracle Flexcube Universal Banking with a CVSS 3.x base score of 4.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-20.
Key facts
- Severity: Medium (CVSS 3.x base score 4.7)
- CVSS v2: 4.3
- EPSS exploit prediction: 2% (73rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-20
- Affected product: Oracle Flexcube Universal Banking
- Published:
- Last modified:
Description
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0 and 12.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle FLEXCUBE Universal Banking, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Universal Banking accessible data. CVSS v3.0 Base Score 4.7 (Integrity impacts).
Frequently asked questions
- What is CVE-2017-3236?
- Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0 and 12.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle FLEXCUBE Universal Banking, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Universal Banking accessible data. CVSS v3.0 Base Score 4.7 (Integrity impacts).
- How severe is CVE-2017-3236?
- CVE-2017-3236 has a CVSS 3.x base score of 4.7, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is none, integrity low, and availability none.
- Is CVE-2017-3236 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (73rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2017-3236?
- CVE-2017-3236 primarily affects Oracle Flexcube Universal Banking. In total, 7 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2017-3236?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2017-3236 published?
- CVE-2017-3236 was published on 2017-01-27 and last updated on 2026-06-17.
References
- http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html
- http://www.securityfocus.com/bid/95552
- http://www.securitytracker.com/id/1037636
Affected products (7)
- cpe:2.3:a:oracle:flexcube_universal_banking:11.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:flexcube_universal_banking:11.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:flexcube_universal_banking:12.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:flexcube_universal_banking:12.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:flexcube_universal_banking:12.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:flexcube_universal_banking:12.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:flexcube_universal_banking:12.2.0:*:*:*:*:*:*:*
More vulnerabilities in Oracle Flexcube Universal Banking
- CVE-2018-2648 — High (CVSS 8.8): Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications…
- CVE-2016-5607 — High (CVSS 8.8): Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications…
- CVE-2020-11987 — High (CVSS 8.2): Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the…
- CVE-2019-2754 — High (CVSS 8.1): Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications…
- CVE-2018-3015 — High (CVSS 8.1): Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications…
- CVE-2018-2649 — High (CVSS 8.1): Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications…
All CVEs affecting Oracle Flexcube Universal Banking →
Other CWE-20 (Improper Input Validation) vulnerabilities
- CVE-2026-48056 — Critical (CVSS 10.0): Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0…
- CVE-2026-33267 — Critical (CVSS 10.0): Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0…
- CVE-2026-47668 — Critical (CVSS 10.0): DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST…
- CVE-2026-16117 — Critical (CVSS 10.0): Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix…
- CVE-2026-48316 — Critical (CVSS 10.0): ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could…
- CVE-2026-48281 — Critical (CVSS 10.0): ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could…
Browse all CWE-20 (Improper Input Validation) vulnerabilities →