Sceawere

Vulnerability Detail

CVE-2026-61097Updated Verified Sceawere Triage Sources: NVD / CISA KEV

OBTFPM Cross-Site Request Forgery

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.6
Creation Date
4h ago
Vendor
Oracle Corporation
Product
Oracle Banking Trade Finance Process Management
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Trade Finance Process Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Trade Finance Process Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Trade Finance Process Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Banking Trade Finance Process Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Trade Finance Process Management.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Banking Trade Finance Process Management product of Oracle Financial Services Applications (component: Common). Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Trade Finance Process Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Trade Finance Process Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Trade Finance Process Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Banking Trade Finance Process Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Trade Finance Process Management. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.6",
  "pubDate": "2026-07-21T22:18:40.790Z",
  "pubdate": "2026-07-21T22:18:40.790Z",
  "executiveSummary": "This vulnerability affects Oracle Banking Trade Finance Process Management (OBTFPM) versions 14.6.0 through 14.8.0. It is a critical security flaw residing within the Common component, permitting unauthenticated remote attackers to perform unauthorized actions against the system.\nThe vulnerability is characterized by a significant scope change (S:C), where successful exploitation not only compromises the OBTFPM platform but may also adversely affect integrated third-party products. The attack vector is via HTTP and requires the interaction of an authenticated victim user, typically through deceptive social engineering or link manipulation.\nThe exploit allows an attacker to manipulate, delete, or exfiltrate critical data, and induces a partial denial of service (DoS) on the target system. With a CVSS 3.1 Base Score of 9.6, the risk is severe, as it facilitates full unauthorized access to sensitive financial data. Organizations are urged to prioritize the application of vendor-supplied security patches to mitigate this high-impact risk.",
  "technicalDetails": "The vulnerability identified in the Common component of Oracle Banking Trade Finance Process Management (OBTFPM) versions 14.6.0-14.8.0 leverages the inherent trust the web application places in a user's browser session. By operating through HTTP, the vulnerability allows an attacker to execute unauthorized requests, effectively bypassing session-based security constraints. The attack relies on an unauthenticated attacker crafting a malicious request, which is then executed within the security context of a legitimate user who has an active session with the OBTFPM interface.\nThe root cause points to improper request validation, likely lacking robust CSRF tokens or equivalent anti-forgery mechanisms. Because the vulnerability involves a scope change (S:C), the application fails to adequately constrain the security boundaries between the OBTFPM instance and its interconnected ecosystem. This allows the attacker to propagate malicious commands beyond the primary application, impacting auxiliary systems.\nExploitation follows a specific workflow: First, the attacker identifies a target user who is authorized to access OBTFPM. Second, the attacker distributes a crafted HTTP request, often through an embedded link or a malicious webpage that triggers an automatic request upon page load. Third, the victim’s browser, unaware of the malicious intent, transmits the request to the OBTFPM server using the victim's legitimate session credentials (e.g., cookies). Finally, the OBTFPM server processes the request as a legitimate action initiated by the victim.\nThe impact of a successful exploitation is comprehensive. Due to the high integrity and confidentiality permissions typically afforded to authenticated users in OBTFPM, an attacker can perform unauthorized CRUD (Create, Read, Update, Delete) operations on sensitive financial data. This results in the potential for complete data exposure or corruption. Furthermore, the ability to trigger a partial denial of service suggests that the attacker can exhaust system resources or disrupt critical processing modules, leading to operational instability. The combination of complete data access and partial system failure makes this a severe threat to the integrity of trade finance workflows. Given that the vulnerability requires user interaction but no authentication from the attacker, the primary defensive hurdle is the reliance on the victim's interaction, which remains a high-probability occurrence in large-scale financial environments."
}
CVE-2026-61097: OBTFPM Cross-Site Request Forgery (CRITICAL Severity, CVSS: 9.6) - Sceawere