CVE-2025-50074Medium· 4.9▾ SunlitVulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Security Management System). Supported versions that are affected are 2.9.0.0.0-7.2.0.0.0. Easil…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Security Management System). Supported versions that are affected are 2.9.0.0.0-7.2.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Financial Services Revenue Management and Billing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financial Services Revenue Management and Billing accessible data. CVSS 3.1 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).
financial_services_revenue_management_and_billing >= 2.9.0.0.0, <= 7.2.0.0.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-50075Medium· 6.5Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Security Management System)
CVE-2026-87225High· 7.1Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)
CVE-2026-87221High· 7.5Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)
CVE-2026-87209High· 7.1Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)
CVE-2025-30758Medium· 5.3Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: User Interface)
CVE-2022-31746Medium· 6.5Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header