Junglewise Threat Intelligence

CVE-2016-8302: Oracle FLEXCUBE Universal Banking information disclosure in Core component

CVE-2016-8302 · Severity: medium · CVSS 4.3 · Published 2017-01-27

Technologies: Oracle Flexcube Universal Banking. Vendors: Oracle.

Executive brief

Oracle FLEXCUBE Universal Banking, a core banking platform used for managing financial operations and customer accounts, contains a security vulnerability in its Core subcomponent. An attacker with low-level access to the network can exploit this flaw to view sensitive banking data that they should not be authorized to see. This could lead to the exposure of confidential customer or financial information, potentially impacting the organization's data privacy compliance and reputation.

Technical details

An information disclosure vulnerability (CWE-200) exists in the Core subcomponent of Oracle FLEXCUBE Universal Banking. The flaw is easily exploitable via the HTTP protocol and requires only low-privileged user credentials. A successful exploit allows a remote attacker to gain unauthorized read access to a subset of data managed by the application. Affected versions include 11.3.0 through 12.2.0. Oracle addressed this issue in the January 2017 Critical Patch Update.

Affected products

  • Oracle FLEXCUBE Universal Banking 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-17: patched: Oracle released the January 2017 Critical Patch Update addressing this issue

References

Related threats