Junglewise Threat Intelligence

CVE-2016-8313: Oracle FLEXCUBE Private Banking information disclosure in Product Search

CVE-2016-8313 · Severity: medium · CVSS 4.1 · Published 2017-01-27

Technologies: Oracle Flexcube Private Banking. Vendors: Oracle.

Executive brief

Oracle FLEXCUBE Private Banking, a platform used by financial institutions to manage wealth and investment services, contains a security vulnerability in its search functionality. A low-privileged user could potentially gain unauthorized access to sensitive banking data by tricking another user into performing a specific action. While the direct impact is limited to reading a subset of data, the breach could potentially affect other integrated systems.

Technical details

A vulnerability in the Product / Instrument Search subcomponent of Oracle FLEXCUBE Private Banking (versions 2.0.1, 2.2.0, and 12.0.1) allows for unauthorized information disclosure. The flaw is classified as CWE-200 (Exposure of Sensitive Information) and is exploitable via the HTTP protocol. An attacker with low privileges can trigger the vulnerability, but successful exploitation requires human interaction from a victim (User Interaction: Required). The vulnerability has a 'Scope: Changed' (S:C) designation, indicating that an attack on this component may impact other security domains or products. The primary impact is a partial loss of confidentiality (C:L).

Affected products

  • Oracle FLEXCUBE Private Banking 2.0.1, 2.2.0, 12.0.1

Timeline

  • 2017-01-27: advisory: Initial NVD publication date
  • 2017-01-17: patched: Addressed in Oracle Critical Patch Update (CPU) January 2017

References

Related threats