Junglewise Threat Intelligence

CVE-2016-8309: Oracle FLEXCUBE Investor Servicing improper access control in Core

CVE-2016-8309 · Severity: medium · CVSS 4.3 · Published 2017-01-27

Technologies: Oracle Flexcube Investor Servicing. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle FLEXCUBE Investor Servicing, a financial platform used for managing investment funds and investor records. An attacker with low-level access to the system can exploit this flaw over the network to view sensitive data they are not authorized to see. This could lead to the exposure of private financial information or internal records.

Technical details

This vulnerability is classified as improper access control (CWE-284) within the Core subcomponent of Oracle FLEXCUBE Investor Servicing. It is easily exploitable by a low-privileged attacker with network access via HTTP. The flaw allows an authenticated user to bypass intended restrictions to perform unauthorized read operations on a subset of the application's data. The vulnerability affects versions 12.0.1 through 12.3.0. Oracle addressed this issue in the January 2017 Critical Patch Update.

Affected products

  • Oracle FLEXCUBE Investor Servicing 12.0.1, 12.0.2, 12.0.4, 12.1.0, 12.3.0

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-17: patched: Oracle January 2017 Critical Patch Update released

References

Related threats