Junglewise Threat Intelligence

CVE-2016-8298: Oracle FLEXCUBE Private Banking improper access control in Product Search

CVE-2016-8298 · Severity: high · CVSS 8.1 · Published 2017-01-27

Technologies: Oracle Flexcube Private Banking. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle FLEXCUBE Private Banking, a platform used by financial institutions to manage wealth and investment services. An attacker with basic user access can exploit this flaw to view, modify, or delete sensitive banking data. This could lead to unauthorized financial transactions, loss of customer data integrity, and significant regulatory or reputational damage.

Technical details

An improper access control vulnerability (CWE-284) exists in the Product / Instrument Search subcomponent of Oracle FLEXCUBE Private Banking. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to gain unauthorized read, create, delete, or modification access to critical data or all accessible data within the application. The vulnerability affects versions 2.0.1, 2.2.0, and 12.0.1. Oracle addressed this issue in the January 2017 Critical Patch Update.

Affected products

  • Oracle FLEXCUBE Private Banking 2.0.1, 2.2.0, 12.0.1

Timeline

  • 2017-01-27: advisory: Initial disclosure by Oracle
  • 2017-01-27: patched: Fix released in January 2017 Critical Patch Update

References

Related threats