Executive brief
A vulnerability exists in Oracle FLEXCUBE Core Banking, a platform used by financial institutions to manage core banking operations and customer transactions. An unauthenticated attacker can exploit this flaw over the network to gain unauthorized access to sensitive banking data. While the attacker cannot modify data or shut down the system, the exposure of confidential information could lead to regulatory compliance issues and reputational damage.
Technical details
The vulnerability is classified as improper access control (CWE-284) within the 'Core' subcomponent of Oracle FLEXCUBE Core Banking. It is easily exploitable by an unauthenticated attacker with network access via HTTP. The flaw allows for the unauthorized retrieval of a subset of data accessible to the FLEXCUBE component. The impact is limited to confidentiality, with no reported impact on data integrity or system availability. Affected versions include 5.1.0, 5.2.0, and 11.5.0. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle FLEXCUBE Core Banking 5.1.0, 5.2.0, 11.5.0
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle January 2017 Critical Patch Update