Executive brief
A critical vulnerability exists in the Oracle One-to-One Fulfillment component of the Oracle E-Business Suite, which manages high-volume personalized communications. An unauthenticated attacker can exploit this flaw over the network to gain full access to sensitive data. This could result in the unauthorized viewing, modification, or deletion of critical business information, potentially compromising customer records and operational integrity.
Technical details
This vulnerability is classified as improper access control (CWE-284) within the Internal Operations subcomponent of Oracle One-to-One Fulfillment. It is easily exploitable by an unauthenticated attacker with network access via HTTP. The flaw allows for unauthorized creation, deletion, or modification of critical data, as well as full read access to all data accessible by the component. The vulnerability affects multiple versions of Oracle E-Business Suite across the 12.1 and 12.2 release cycles. Oracle addressed this issue in the January 2017 Critical Patch Update.
Affected products
- Oracle One-to-One Fulfillment 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update January 2017 released