Executive brief
Oracle FLEXCUBE Universal Banking, a core banking platform used for managing financial transactions and customer accounts, contains a security vulnerability in its Core subcomponent. An unauthenticated attacker can exploit this over the network to view, modify, or delete sensitive banking data. This could lead to unauthorized financial records changes or a partial disruption of banking services.
Technical details
A vulnerability in the Core subcomponent of Oracle FLEXCUBE Universal Banking allows an unauthenticated attacker with network access via HTTP to compromise the system. The flaw is classified under CWE-254 (Security Features) and is considered easily exploitable without user interaction. An attacker can achieve unauthorized read, update, insert, or delete access to a subset of the application's data. Additionally, the vulnerability can be used to cause a partial denial of service (DoS). The issue affects multiple versions ranging from 11.3.0 to 12.2.0 and was addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle FLEXCUBE Universal Banking 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update published