Junglewise Threat Intelligence

CVE-2016-8304: Oracle FLEXCUBE Universal Banking improper access control in Core

CVE-2016-8304 · Severity: medium · CVSS 5.4 · Published 2017-01-27

Technologies: Oracle Flexcube Universal Banking. Vendors: Oracle.

Executive brief

Oracle FLEXCUBE Universal Banking, a core banking platform used for managing financial operations and customer accounts, contains a security vulnerability in its Core subcomponent. A low-privileged user could exploit this flaw to gain unauthorized access to view, modify, or delete certain banking data. Successful exploitation requires a legitimate user to interact with a malicious link or page, which could potentially allow the attacker to impact other integrated systems beyond the banking software itself.

Technical details

This vulnerability in the Core subcomponent of Oracle FLEXCUBE Universal Banking is classified as an improper access control issue (CWE-284). It is exploitable by a low-privileged attacker with network access via HTTP, but requires human interaction from a victim (User Interaction: Required). The vulnerability has a 'Changed' Scope (S:C), meaning an exploit can impact components beyond the security scope of FLEXCUBE. Attackers can achieve unauthorized read access to a subset of data and unauthorized update, insert, or delete access to some accessible data. The issue affects versions 11.3.0 through 12.2.0 and was addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle FLEXCUBE Universal Banking 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats