Junglewise Threat Intelligence

CVE-2016-8325: Oracle One-to-One Fulfillment improper access control in Internal Operations

CVE-2016-8325 · Severity: critical · CVSS 9.1 · Published 2017-01-27

Technologies: Oracle One-To-One Fulfillment. Vendors: Oracle.

Executive brief

A critical vulnerability exists in the Oracle One-to-One Fulfillment component of the Oracle E-Business Suite, which manages high-volume personalized communications. An unauthenticated attacker can exploit this flaw over the network to gain full access to sensitive data. This could result in the unauthorized viewing, modification, or deletion of critical business information, potentially compromising customer records and operational integrity.

Technical details

This vulnerability is classified as improper access control (CWE-284) within the Internal Operations subcomponent of Oracle One-to-One Fulfillment. It is easily exploitable by an unauthenticated attacker with network access via HTTP. The flaw allows for unauthorized creation, deletion, or modification of critical data, as well as full read access to all data accessible by the component. The vulnerability affects multiple versions of Oracle E-Business Suite across the 12.1 and 12.2 release cycles. Oracle addressed this issue in the January 2017 Critical Patch Update.

Affected products

  • Oracle One-to-One Fulfillment 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update January 2017 released

References

Related threats