Junglewise Threat Intelligence

CVE-2016-8297: Oracle FLEXCUBE Universal Banking improper access control in Core

CVE-2016-8297 · Severity: high · CVSS 8.1 · Published 2017-01-27

Technologies: Oracle Flexcube Universal Banking. Vendors: Oracle.

Executive brief

A vulnerability in Oracle's FLEXCUBE Universal Banking software could allow an authorized user with low-level permissions to gain unauthorized access to sensitive financial data. This flaw affects the core component of the banking platform, potentially allowing attackers to view, modify, or delete critical banking records. Such an exploit could lead to significant data breaches or unauthorized financial transactions, impacting the institution's operational integrity and reputation.

Technical details

An improper access control vulnerability (CWE-284) exists in the Core subcomponent of Oracle FLEXCUBE Universal Banking. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to bypass intended security restrictions to achieve unauthorized creation, deletion, or modification of critical data, as well as complete read access to all accessible data within the application. The vulnerability affects multiple versions ranging from 11.3.0 to 12.2.0. Oracle addressed this issue in the January 2017 Critical Patch Update.

Affected products

  • Oracle FLEXCUBE Universal Banking 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle January 2017 Critical Patch Update released

References

Related threats