Junglewise Threat Intelligence

CVE-2016-8301: Oracle FLEXCUBE Universal Banking integrity vulnerability in Core

CVE-2016-8301 · Severity: medium · CVSS 4.3 · Published 2017-01-27

Technologies: Oracle Flexcube Universal Banking. Vendors: Oracle.

Executive brief

Oracle FLEXCUBE Universal Banking, a core banking platform used for managing financial transactions and customer data, contains a security vulnerability in its Core subcomponent. An unauthenticated attacker could trick a legitimate user into performing an action that allows the attacker to modify, insert, or delete certain banking data. While the attacker cannot view sensitive information, this could lead to unauthorized changes in financial records or system configurations.

Technical details

This vulnerability exists in the Core subcomponent of Oracle FLEXCUBE Universal Banking. It is classified as an 'easily exploitable' flaw that allows an unauthenticated attacker with network access via HTTP to impact the integrity of the system. The exploit requires human interaction from a person other than the attacker (typically a legitimate user), suggesting a vulnerability class such as Cross-Site Request Forgery (CSRF) or a similar UI-based attack. Successful exploitation can result in unauthorized update, insert, or delete access to a subset of FLEXCUBE Universal Banking data. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle FLEXCUBE Universal Banking 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-17: patched: Addressed in Oracle January 2017 Critical Patch Update

References

Related threats