Executive brief
A vulnerability exists in Oracle FLEXCUBE Investor Servicing, a financial platform used for managing investment funds and investor records. An attacker with low-level access to the network can exploit this flaw to view, modify, or delete sensitive financial data. This could lead to significant data breaches or unauthorized changes to critical investment records.
Technical details
An improper access control vulnerability (CWE-284) exists in the Infrastructure Code subcomponent of Oracle FLEXCUBE Investor Servicing. The flaw is easily exploitable via the HTTP protocol by a low-privileged attacker with network access. Successful exploitation allows the attacker to gain unauthorized creation, deletion, or modification access to critical data, as well as full read access to all data accessible by the component. The vulnerability affects versions 12.0.1 through 12.3.0 and was addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle FLEXCUBE Investor Servicing 12.0.1, 12.0.2, 12.0.4, 12.1.0, 12.3.0
Timeline
- 2017-01-27: disclosed: Initial NVD publication
- 2017-01-27: advisory: Oracle Critical Patch Update published