Junglewise Threat Intelligence

CVE-2016-8306: Oracle FLEXCUBE Investor Servicing data manipulation in Core component

CVE-2016-8306 · Severity: medium · CVSS 5.4 · Published 2017-01-27

Technologies: Oracle Flexcube Investor Servicing. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle FLEXCUBE Investor Servicing, a platform used by financial institutions to manage investment records and investor activities. An attacker with low-level access to the network can exploit this flaw to view, modify, or delete sensitive financial data. This could lead to unauthorized changes in investor records or the exposure of private financial information.

Technical details

A vulnerability in the Core subcomponent of Oracle FLEXCUBE Investor Servicing (versions 12.0.1 through 12.3.0) allows for unauthorized data manipulation. The flaw is categorized under CWE-254 (Security Features) and is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables the attacker to perform unauthorized updates, insertions, or deletions of certain data, as well as gain unauthorized read access to a subset of the system's data. The vulnerability was addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle FLEXCUBE Investor Servicing 12.0.1, 12.0.2, 12.0.4, 12.1.0, 12.3.0

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats