← Vulnerability feed

Vulnerability record · CVE-2016-8323 · published 27 January 2017

CVE-2016-8323: Oracle flexcube core banking improper access control vulnerability

Oracle · Flexcube Core Banking

Vulnerability in the Oracle FLEXCUBE Core Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 5.1.0, 5.2.0 and 11.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Core Banking. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Core Banking accessible data as well as unauthorized read access to a subset of Oracle FLEXCUBE Core Banking accessible data. CVSS v3.0 Base Score 5.4 (Confidentiality and Integrity impacts).

5.4 CVSS 3.0 Medium EPSS 0.93% · top 40.9% CWE-284 · Improper access control
5.4CVSS 3.0 base score, v2 5.5
0.93%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Vulnerability in the Oracle FLEXCUBE Core Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 5.1.0, 5.2.0 and 11.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Core Banking. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Core Banking accessible data as well as unauthorized read access to a subset of Oracle FLEXCUBE Core Banking accessible data. CVSS v3.0 Base Score 5.4 (Confidentiality and Integrity impacts).

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-8323 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-10683Dom4j project dom4j xml external entity (xxe) vulnerabilitydom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is po…EPSS 7.3%7.5CVE-2019-0227Apache Axis 1.4 SSRF via AdminService (expired domain)Apache Axis 1.4, last released in 2006, contains a server-side request forgery flaw in its AdminService. The service can be induced to fetch a remote…EPSS 92%analysed7.0CVE-2020-27216Eclipse jetty vulnerabilityIn Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the…EPSS 4.4%6.3CVE-2020-2955Oracle flexcube core banking vulnerabilityVulnerability in the Oracle FLEXCUBE Core Banking product of Oracle Financial Services Applications (component: Transaction Processing). The supporte…EPSS 0.90%6.1CVE-2019-10241Eclipse jetty cross-site scripting vulnerabilityIn Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES…EPSS 9.6%6.1CVE-2018-8032Apache axis cross-site scripting vulnerabilityApache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.EPSS 11%6.1CVE-2018-2807Oracle flexcube core banking vulnerabilityVulnerability in the Oracle FLEXCUBE Core Banking component of Oracle Financial Services Applications (subcomponent: Securities). Supported versions …EPSS 1.4%5.3CVE-2019-10246Eclipse jetty information exposure vulnerabilityIn Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource dir…EPSS 4.1%

Source: NIST National Vulnerability Database (record CVE-2016-8323), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.