Executive brief
Oracle FLEXCUBE Investor Servicing, a financial application used for managing investment funds and transfer agency operations, contains a security vulnerability in its core component. An unauthenticated attacker could exploit this flaw to gain unauthorized access to view, modify, or delete sensitive financial data. Successful exploitation requires a legitimate user to perform a specific action, such as clicking a malicious link, and could potentially impact other integrated business systems.
Technical details
A vulnerability in the Core subcomponent of Oracle FLEXCUBE Investor Servicing (versions 12.0.1 through 12.3.0) allows an unauthenticated remote attacker to impact the system via HTTP. The vulnerability is classified under improper access control (CWE-284) and requires human interaction from a person other than the attacker (User Interaction: Required). Successful exploitation allows unauthorized read, update, insert, or delete access to a subset of accessible data. Notably, the vulnerability has a 'Changed' scope (S:C), indicating that an attack on FLEXCUBE could potentially impact additional integrated products or the underlying environment. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle FLEXCUBE Investor Servicing 12.0.1, 12.0.2, 12.0.4, 12.1.0, 12.3.0
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle January 2017 Critical Patch Update published