Executive brief
Oracle FLEXCUBE Universal Banking, a core banking platform used for managing financial operations and customer data, contains a security vulnerability in its Core subcomponent. An unauthenticated attacker could exploit this flaw to gain unauthorized access to view, modify, or delete sensitive banking data. Successful exploitation requires a legitimate user to perform a specific action, such as clicking a malicious link, and could potentially impact other integrated systems.
Technical details
A vulnerability in the Core subcomponent of Oracle FLEXCUBE Universal Banking allows unauthenticated attackers with network access via HTTP to compromise the system. The flaw is characterized by a 'Changed' scope in CVSS metrics, suggesting it may be a Cross-Site Scripting (XSS) or similar injection vulnerability that allows an attacker to impact components beyond the immediate application. Successful exploitation requires user interaction (UI:R) from a person other than the attacker. If successful, the attacker can achieve unauthorized read access to a subset of data and unauthorized update, insert, or delete access to some accessible data. The vulnerability affects versions 11.3.0 through 12.2.0 and was addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle FLEXCUBE Universal Banking 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0
Timeline
- 2017-01-27: advisory: Initial disclosure in Oracle Critical Patch Update
- 2017-01-27: disclosed