Junglewise Threat Intelligence

CVE-2017-3235: Oracle FLEXCUBE Universal Banking data manipulation via physical access

CVE-2017-3235 · Severity: low · CVSS 3.5 · Published 2017-01-27

Technologies: Oracle Flexcube Universal Banking. Vendors: Oracle.

Executive brief

Oracle FLEXCUBE Universal Banking, a core banking platform used for managing financial transactions and customer data, contains a vulnerability that can be exploited by someone with physical access to the system. An unauthorized person could potentially read, modify, or delete sensitive banking data. While the risk is limited to those with physical proximity to the hardware, it could lead to unauthorized data manipulation or information disclosure.

Technical details

A vulnerability in the Core subcomponent of Oracle FLEXCUBE Universal Banking allows for unauthorized data access and modification. The flaw is categorized as easily exploitable but requires the 'Physical' attack vector, meaning the attacker must have physical access to the device or infrastructure where the software is running. Successful exploitation enables an attacker to perform unauthorized read, update, insert, or delete operations on a subset of the application's data. The vulnerability affects multiple versions ranging from 11.3.0 to 12.2.0 and was addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle FLEXCUBE Universal Banking 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats