Executive brief
Oracle FLEXCUBE Investor Servicing is a financial platform used for managing investment funds and investor records. A vulnerability in the 'Core' component could allow an authorized user with low-level access to trick another person into performing actions that compromise the system. If exploited, this could lead to unauthorized viewing, modification, or deletion of sensitive financial data.
Technical details
This vulnerability exists in the Core subcomponent of Oracle FLEXCUBE Investor Servicing (versions 12.0.1 through 12.3.0). It is classified as an improper access control issue (CWE-284) that is exploitable over the network via HTTP. An attacker requires low-level privileges and must successfully induce a different user to interact with a malicious link or request (User Interaction: Required). Successful exploitation allows the attacker to gain unauthorized read, update, insert, or delete access to a subset of data. The vulnerability also carries a 'Scope' impact, meaning an exploit could potentially affect components or products beyond the immediate FLEXCUBE environment.
Affected products
- Oracle FLEXCUBE Investor Servicing 12.0.1, 12.0.2, 12.0.4, 12.1.0, 12.3.0
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-17: patched: Oracle Critical Patch Update (CPU) released