Executive brief
A vulnerability in the Core subcomponent of Oracle FLEXCUBE Universal Banking could allow an individual with physical access to the system to view sensitive information. This banking platform is used for managing core financial operations, and an exploit could lead to the unauthorized disclosure of a limited amount of customer or operational data. Successful exploitation requires interaction from a legitimate user other than the attacker.
Technical details
This vulnerability is classified as an information exposure (CWE-200) within the Core subcomponent of Oracle FLEXCUBE Universal Banking. It is exploitable only via physical access to the target system and requires human interaction from a person other than the attacker (UI:R). The root cause is not specified beyond its location in the Core subcomponent. Successful exploitation results in a low impact on confidentiality, allowing the attacker to read a subset of accessible data, while integrity and availability remain unaffected. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle FLEXCUBE Universal Banking 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0
Timeline
- 2017-01-27: advisory: Initial NVD publication date
- 2017-01-17: patched: Addressed in Oracle January 2017 Critical Patch Update