Junglewise Threat Intelligence

CVE-2016-8299: Oracle FLEXCUBE Universal Banking improper access control in Core

CVE-2016-8299 · Severity: medium · CVSS 6.3 · Published 2017-01-27

Technologies: Oracle Flexcube Universal Banking. Vendors: Oracle.

Executive brief

Oracle FLEXCUBE Universal Banking, a core banking platform used by financial institutions to manage retail and corporate banking operations, contains a security vulnerability in its Core subcomponent. An attacker with low-level user credentials can exploit this flaw over the network to view, modify, or delete sensitive banking data. Additionally, an exploit could cause a partial service outage, potentially disrupting banking operations and impacting data integrity.

Technical details

An improper access control vulnerability (CWE-284) exists in the Core subcomponent of Oracle FLEXCUBE Universal Banking. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to perform unauthorized read, update, insert, or delete operations on a subset of the application's data. It also enables the attacker to trigger a partial denial of service (DoS) condition. The vulnerability affects multiple versions ranging from 11.3.0 to 12.2.0 and was addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle FLEXCUBE Universal Banking 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-17: patched: Addressed in Oracle January 2017 Critical Patch Update

References

Related threats