at the very least they will probably have sufficient privileges to allow an intruder to perform a denial of service attack through filling the available database space.
At worst, if an intruder uses a highly privileged account, it may additionally allow users to change application data directly and avoid all application-level auditing and privileges. This would lead to poor decision-making and may lead to inconsistencies in the financial information. All users that have Oracle have SQL*Plus installed by default. This tool alone would allow any legitimate applications user to attempt to guess database account and password combinations, as would Microsoft Access. Users do not have to be Database Administrators to have these tools available to them.