Junglewise Threat Intelligence

CVE-2016-8320: Oracle FLEXCUBE Enterprise Limits and Collateral Management improper access control in Core

CVE-2016-8320 · Severity: medium · CVSS 6.1 · Published 2017-01-27

Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle FLEXCUBE Enterprise Limits and Collateral Management, a financial software suite used for managing credit limits and collateral. An attacker could trick a legitimate user into performing an action that allows the attacker to view, modify, or delete sensitive financial data. This could lead to unauthorized changes in credit records or the exposure of confidential customer information.

Technical details

This vulnerability affects the Core subcomponent of Oracle FLEXCUBE Enterprise Limits and Collateral Management versions 12.0.0 and 12.0.2. It is classified as an improper access control issue (CWE-284) that is exploitable over the network via HTTP without authentication. The attack requires user interaction (UI:R) and has a changed scope (S:C), suggesting it may be a Cross-Site Scripting (XSS) or similar injection flaw that allows an attacker to impact additional products beyond the primary application. Successful exploitation enables unauthorized read, update, insert, or delete access to a subset of the application's data. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle FLEXCUBE Enterprise Limits and Collateral Management 12.0.0, 12.0.2

Timeline

  • 2017-01-17: advisory: Oracle Critical Patch Update released
  • 2017-01-27: disclosed: NVD publication date

References