Junglewise Threat Intelligence

CVE-2016-8314: Oracle FLEXCUBE Core Banking information disclosure in Core subcomponent

CVE-2016-8314 · Severity: low · CVSS 3.1 · Published 2017-01-27

Technologies: Oracle Flexcube Core Banking. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle FLEXCUBE Core Banking, a platform used by financial institutions to manage core banking operations and customer transactions. A low-privileged user could potentially gain unauthorized access to a limited subset of sensitive banking data. While the impact is restricted to data confidentiality, it could lead to the exposure of private financial information.

Technical details

This vulnerability affects the Core subcomponent of Oracle FLEXCUBE Core Banking versions 5.1.0, 5.2.0, and 11.5.0. It is classified as difficult to exploit (High Attack Complexity) and requires the attacker to have low-level authenticated privileges. The attack vector is network-based via HTTP. Successful exploitation results in a partial loss of confidentiality, allowing the attacker to read a subset of data they should not have access to. The vulnerability was addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle FLEXCUBE Core Banking 5.1.0, 5.2.0, 11.5.0

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats