Junglewise Threat Intelligence

CVE-2016-8323: Oracle FLEXCUBE Core Banking improper access control in Core subcomponent

CVE-2016-8323 · Severity: medium · CVSS 5.4 · Published 2017-01-27

Technologies: Oracle Flexcube Core Banking. Vendors: Oracle.

Executive brief

A vulnerability in Oracle FLEXCUBE Core Banking allows an authorized user with low-level permissions to access or modify sensitive banking data. This could lead to unauthorized changes to financial records or the exposure of private customer information. The issue affects the core component of the banking platform and can be exploited over the network.

Technical details

An improper access control vulnerability (CWE-284) exists in the Core subcomponent of Oracle FLEXCUBE Core Banking. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to perform unauthorized read, update, insert, or delete operations on a subset of the application's data. The vulnerability affects versions 5.1.0, 5.2.0, and 11.5.0. Oracle addressed this issue in the January 2017 Critical Patch Update.

Affected products

  • Oracle FLEXCUBE Core Banking 5.1.0, 5.2.0, 11.5.0

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle January 2017 Critical Patch Update released

References

Related threats