Junglewise Threat Intelligence

CVE-2016-5623: Oracle FLEXCUBE Private Banking data manipulation in Product Search

CVE-2016-5623 · Severity: medium · CVSS 5.4 · Published 2017-01-27

Technologies: Oracle Flexcube Private Banking. Vendors: Oracle.

Executive brief

Oracle FLEXCUBE Private Banking, a platform used by financial institutions to manage wealth and investment services, contains a security vulnerability in its search functionality. An authorized user with low-level permissions could exploit this flaw to view, modify, or delete certain banking data they should not have access to. This could lead to unauthorized changes to financial records or the exposure of sensitive client information.

Technical details

A vulnerability exists in the Product / Instrument Search subcomponent of Oracle FLEXCUBE Private Banking (versions 2.0.1, 2.2.0, and 12.0.1). The flaw is categorized under CWE-254 (Security Features) and allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation enables the attacker to perform unauthorized update, insert, or delete operations on a subset of accessible data, as well as unauthorized read access. The attack does not require user interaction. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle FLEXCUBE Private Banking 2.0.1, 2.2.0, 12.0.1

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle January 2017 Critical Patch Update released

References

Related threats