Executive brief
Oracle FLEXCUBE Universal Banking, a core banking platform used by financial institutions to manage retail and corporate banking operations, contains a security vulnerability in its Core subcomponent. An attacker with low-level user credentials can exploit this flaw over the network to view, modify, or delete sensitive banking data. Additionally, an exploit could cause a partial service outage, potentially disrupting banking operations and impacting data integrity.
Technical details
An improper access control vulnerability (CWE-284) exists in the Core subcomponent of Oracle FLEXCUBE Universal Banking. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to perform unauthorized read, update, insert, or delete operations on a subset of the application's data. It also enables the attacker to trigger a partial denial of service (DoS) condition. The vulnerability affects multiple versions ranging from 11.3.0 to 12.2.0 and was addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle FLEXCUBE Universal Banking 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-17: patched: Addressed in Oracle January 2017 Critical Patch Update