Executive brief
Oracle FLEXCUBE Investor Servicing is a financial services platform used for managing investment portfolios and investor records. A vulnerability in the 'Core' component could allow an authorized user with low-level access to view sensitive data they are not supposed to see. While the risk is limited to specific subsets of data and requires specific conditions to exploit, it could lead to unauthorized disclosure of financial information.
Technical details
A vulnerability exists in the Core subcomponent of Oracle FLEXCUBE Investor Servicing (versions 12.0.1 through 12.3.0). The flaw is accessible via the HTTP protocol and requires the attacker to have low-privileged credentials. Exploitation is considered difficult (High Attack Complexity) but can result in unauthorized read access to a subset of data within the application. The vulnerability was addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle FLEXCUBE Investor Servicing 12.0.1, 12.0.2, 12.0.4, 12.1.0, 12.3.0
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-17: patched: Addressed in Oracle Critical Patch Update (CPU) January 2017