Executive brief
Oracle FLEXCUBE Private Banking is a financial services platform used for managing wealth and investment portfolios. A vulnerability in the search functionality allows an authorized user with low-level access to view sensitive information they are not supposed to see. This could lead to the exposure of private financial data or instrument details, potentially impacting client confidentiality.
Technical details
An information disclosure vulnerability (CWE-200) exists in the Product / Instrument Search subcomponent of Oracle FLEXCUBE Private Banking. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to bypass intended access controls and perform unauthorized read operations on a subset of the application's data. The vulnerability affects versions 2.0.1, 2.2.0, and 12.0.1. Oracle addressed this issue in the January 2017 Critical Patch Update.
Affected products
- Oracle FLEXCUBE Private Banking 2.0.1, 2.2.0, 12.0.1
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update January 2017 released