Executive brief
Oracle FLEXCUBE Universal Banking, a core banking platform used by financial institutions to manage retail and corporate banking operations, contains a security vulnerability. An unauthenticated attacker can exploit this flaw over the network to gain unauthorized access to sensitive banking data. This could lead to the exposure of confidential customer or financial information, potentially impacting the organization's regulatory compliance and reputation.
Technical details
A vulnerability in the Core subcomponent of Oracle FLEXCUBE Universal Banking (classified as improper access control, CWE-284) allows for unauthorized data retrieval. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation results in unauthorized read access to a subset of FLEXCUBE Universal Banking accessible data, impacting confidentiality. Affected versions include 11.3.0 through 12.2.0. Oracle addressed this issue in the January 2017 Critical Patch Update.
Affected products
- Oracle FLEXCUBE Universal Banking 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle January 2017 Critical Patch Update released