Junglewise Threat Intelligence

CVE-2016-8322: Oracle FLEXCUBE Core Banking information disclosure in Core component

CVE-2016-8322 · Severity: medium · CVSS 4.3 · Published 2017-01-27

Technologies: Oracle Flexcube Core Banking. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle FLEXCUBE Core Banking, a platform used by financial institutions to manage core banking operations and customer transactions. An attacker with low-level access to the network can exploit this flaw to view sensitive banking data that they should not be authorized to see. This could lead to the exposure of private financial information or internal banking records.

Technical details

An information disclosure vulnerability (CWE-200) exists in the Core subcomponent of Oracle FLEXCUBE Core Banking versions 5.1.0, 5.2.0, and 11.5.0. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to bypass intended access controls to read a subset of data within the FLEXCUBE environment. The vulnerability has been addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle FLEXCUBE Core Banking 5.1.0, 5.2.0, 11.5.0

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-17: patched: Addressed in Oracle January 2017 Critical Patch Update

References

Related threats