Junglewise Threat Intelligence

CVE-2016-8315: Oracle FLEXCUBE Investor Servicing improper access control in Infrastructure Code

CVE-2016-8315 · Severity: high · CVSS 8.1 · Published 2017-01-27

Technologies: Oracle Flexcube Investor Servicing. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle FLEXCUBE Investor Servicing, a financial platform used for managing investment funds and investor records. An attacker with low-level access to the network can exploit this flaw to view, modify, or delete sensitive financial data. This could lead to significant data breaches or unauthorized changes to critical investment records.

Technical details

An improper access control vulnerability (CWE-284) exists in the Infrastructure Code subcomponent of Oracle FLEXCUBE Investor Servicing. The flaw is easily exploitable via the HTTP protocol by a low-privileged attacker with network access. Successful exploitation allows the attacker to gain unauthorized creation, deletion, or modification access to critical data, as well as full read access to all data accessible by the component. The vulnerability affects versions 12.0.1 through 12.3.0 and was addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle FLEXCUBE Investor Servicing 12.0.1, 12.0.2, 12.0.4, 12.1.0, 12.3.0

Timeline

  • 2017-01-27: disclosed: Initial NVD publication
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats