Executive brief
A vulnerability in Oracle FLEXCUBE Universal Banking, a core banking platform, could allow an authorized user with low-level permissions to access sensitive financial data. An attacker could exploit this to view critical information they are not supposed to see, potentially compromising customer privacy and regulatory compliance. The issue affects the 'Core' subcomponent of the banking suite.
Technical details
An improper access control vulnerability (CWE-284) exists in the Core subcomponent of Oracle FLEXCUBE Universal Banking. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to bypass intended security restrictions to gain unauthorized access to critical data or complete access to all data accessible by the FLEXCUBE component. The vulnerability affects multiple versions ranging from 11.3.0 to 12.2.0 and was addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle FLEXCUBE Universal Banking 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-17: patched: Addressed in Oracle Critical Patch Update (CPU) January 2017