Junglewise Threat Intelligence

CVE-2016-8317: Oracle FLEXCUBE Investor Servicing improper access control in Unit Trust

CVE-2016-8317 · Severity: medium · CVSS 5.3 · Published 2017-01-27

Technologies: Oracle Flexcube Investor Servicing. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle FLEXCUBE Investor Servicing, a platform used by financial institutions to manage investment portfolios and unit trusts. An attacker with low-level access to the system could potentially modify, create, or delete critical financial data. This could lead to significant data integrity issues and unauthorized changes to investor records or transaction history.

Technical details

This vulnerability is classified as an improper access control issue (CWE-284) within the Unit Trust subcomponent of Oracle FLEXCUBE Investor Servicing. It is reachable via the HTTP protocol and requires the attacker to have low-privileged credentials. While the attack complexity is rated as high, a successful exploit allows an attacker to perform unauthorized creation, deletion, or modification of all accessible data within the component. The impact is limited to data integrity, with no reported impact on confidentiality or availability. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle FLEXCUBE Investor Servicing 12.0.1, 12.0.2, 12.0.4, 12.1.0, 12.3.0

Timeline

  • 2017-01-27: advisory: Initial disclosure in Oracle Critical Patch Update
  • 2017-01-27: disclosed

References

Related threats