PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-8310 Oracle CVE debrief

CVE-2016-8310 affects Oracle FLEXCUBE Universal Banking and is described by NVD as a network-exploitable, unauthenticated issue reachable over HTTP. Oracle and NVD list supported affected versions across several FLEXCUBE releases, and the impact includes unauthorized read and write access to some data plus partial denial of service. The CVSS v3.0 base score is 7.3, which makes this a high-priority remediation item for exposed banking environments.

Vendor
Oracle
Product
CVE-2016-8310
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-27
Original CVE updated
2026-05-13
Advisory published
2017-01-27
Advisory updated
2026-05-13

Who should care

Oracle FLEXCUBE Universal Banking administrators, financial application owners, patch management teams, and security teams responsible for internet- or intranet-facing banking services should prioritize this issue.

Technical summary

NVD classifies the flaw with CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L and CWE-254. The vulnerability affects Oracle FLEXCUBE Universal Banking versions 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, and 12.2.0. Oracle’s January 2017 CPU is the referenced vendor remediation source in the supplied corpus.

Defensive priority

High

Recommended defensive actions

  • Review the Oracle January 2017 CPU advisory and apply the vendor remediation to all affected FLEXCUBE deployments.
  • Inventory FLEXCUBE Universal Banking versions and confirm whether any listed affected release is in use.
  • Restrict network exposure to the application, especially HTTP access paths, until remediation is complete.
  • Monitor for unexpected data changes, read activity, and signs of partial denial of service in affected environments.
  • Validate compensating controls and document any systems that cannot be immediately patched.

Evidence notes

This debrief is based on the supplied NVD record and Oracle CPU reference. NVD published the CVE on 2017-01-27 and lists the affected versions, CVSS vector, and CWE-254 classification. The Oracle CPU January 2017 advisory is the vendor reference cited in the source corpus. No exploit details are included here.

Official resources

Publicly disclosed in the NVD record on 2017-01-27; the supplied source corpus also references Oracle's January 2017 CPU advisory. NVD last modified the record on 2026-05-13.