Executive brief
A vulnerability exists in Oracle FLEXCUBE Private Banking, a platform used by financial institutions to manage wealth and investment services. An unauthenticated attacker could trick a legitimate user into performing an action that allows the attacker to modify, add, or delete sensitive banking data. This could lead to unauthorized changes in financial records or instrument data, potentially impacting the integrity of banking operations.
Technical details
A vulnerability in the Product / Instrument Search subcomponent of Oracle FLEXCUBE Private Banking (versions 2.0.1, 2.2.0, and 12.0.1) allows an unauthenticated attacker with network access via HTTP to compromise the system. The exploit requires human interaction from a person other than the attacker, suggesting a UI-based attack such as Cross-Site Request Forgery (CSRF) or a similar client-side injection. Successful exploitation can result in unauthorized update, insert, or delete access to a subset of FLEXCUBE Private Banking data. The vulnerability has a CVSS v3.0 base score of 4.3, primarily impacting data integrity. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle FLEXCUBE Private Banking 2.0.1, 2.2.0, 12.0.1
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-17: patched: Addressed in Oracle January 2017 Critical Patch Update