Executive brief
A vulnerability in Oracle FLEXCUBE Private Banking, a platform used by financial institutions to manage wealth and investment services, could allow an unauthorized person to access or modify sensitive banking data. An attacker could potentially view all accessible private banking information or change certain records if they can trick a legitimate user into performing a specific action, such as clicking a malicious link. This could lead to significant data breaches and unauthorized changes to financial records.
Technical details
An improper access control vulnerability exists in the Product / Instrument Search subcomponent of Oracle FLEXCUBE Private Banking. The flaw is exploitable by an unauthenticated attacker with network access via HTTP, though it requires human interaction from a victim (User Interaction: Required). Successful exploitation can lead to a scope change (Scope: Changed), potentially impacting integrated products beyond the primary application. An attacker can achieve unauthorized read access to all accessible data and unauthorized update or delete access to a subset of the data. The vulnerability affects versions 2.0.1, 2.2.0, and 12.0.1 and was addressed in the Oracle January 2017 Critical Patch Update.
Affected products
- Oracle FLEXCUBE Private Banking 2.0.1, 2.2.0, 12.0.1
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update January 2017