Executive brief
Oracle FLEXCUBE Private Banking, a platform used by financial institutions to manage wealth and investment services, contains a security vulnerability in its search functionality. An attacker can exploit this flaw to trick a legitimate user into performing unintended actions, potentially allowing the attacker to view, modify, or delete sensitive banking data. This could lead to unauthorized financial record changes or the exposure of private client information.
Technical details
A vulnerability exists in the Product / Instrument Search subcomponent of Oracle FLEXCUBE Private Banking (versions 2.0.1, 2.2.0, and 12.0.1). The flaw is classified under improper access control and is exploitable via the network over HTTP without authentication. Successful exploitation requires interaction from a user other than the attacker (User Interaction: Required) and features a 'Changed' Scope, meaning the impact can extend beyond the FLEXCUBE application itself. Attackers can achieve unauthorized read access to a subset of data and unauthorized update, insert, or delete access to some accessible data. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle FLEXCUBE Private Banking 2.0.1, 2.2.0, 12.0.1
Timeline
- 2017-01-27: advisory: Initial NVD publication date
- 2017-01-17: patched: Addressed in Oracle January 2017 Critical Patch Update