Executive brief
Oracle FLEXCUBE Private Banking is a platform used by financial institutions to manage wealth and investment services for high-net-worth clients. A vulnerability in the product search feature could allow an authorized user with low-level permissions to gain unauthorized access to sensitive financial data. This could lead to the exposure of critical customer information and private banking records.
Technical details
An improper access control vulnerability (CWE-284) exists in the Product / Instrument Search subcomponent of Oracle FLEXCUBE Private Banking. The flaw can be exploited by a low-privileged attacker with network access via HTTP. While the vulnerability is classified as difficult to exploit, a successful attack allows for the unauthorized retrieval of critical data or complete access to all data accessible by the FLEXCUBE Private Banking component. The impact is limited to confidentiality, with no reported impact on system integrity or availability. Affected versions include 2.0.1, 2.2.0, and 12.0.1.
Affected products
- Oracle FLEXCUBE Private Banking 2.0.1, 2.2.0, 12.0.1
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update (CPU) January 2017