Executive brief
Oracle FLEXCUBE Universal Banking, a core banking platform used for managing financial operations and customer accounts, contains a security vulnerability in its Core subcomponent. A low-privileged user could exploit this flaw to gain unauthorized access to view, modify, or delete certain banking data. Successful exploitation requires a legitimate user to interact with a malicious link or page, which could potentially allow the attacker to impact other integrated systems beyond the banking software itself.
Technical details
This vulnerability in the Core subcomponent of Oracle FLEXCUBE Universal Banking is classified as an improper access control issue (CWE-284). It is exploitable by a low-privileged attacker with network access via HTTP, but requires human interaction from a victim (User Interaction: Required). The vulnerability has a 'Changed' Scope (S:C), meaning an exploit can impact components beyond the security scope of FLEXCUBE. Attackers can achieve unauthorized read access to a subset of data and unauthorized update, insert, or delete access to some accessible data. The issue affects versions 11.3.0 through 12.2.0 and was addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle FLEXCUBE Universal Banking 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update published