Executive brief
Oracle FLEXCUBE Universal Banking, a core banking platform used for managing financial transactions and customer data, contains a security vulnerability. An unauthenticated attacker could trick a legitimate user into performing an action that allows the attacker to modify, insert, or delete certain banking data. While the attacker cannot view sensitive information, this could lead to unauthorized changes in financial records or operational data.
Technical details
A vulnerability in the Core subcomponent of Oracle FLEXCUBE Universal Banking (versions 11.3.0 through 12.2.0) is classified as improper input validation (CWE-20). The flaw is accessible via HTTP and does not require authentication, though it does require human interaction from a legitimate user (UI:R) to be successful. The vulnerability has a 'Changed' scope (S:C), meaning an exploit can impact components beyond the immediate banking application. Successful exploitation allows an attacker to perform unauthorized updates, insertions, or deletions of data, impacting the integrity of the system. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle FLEXCUBE Universal Banking 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0
Timeline
- 2017-01-27: advisory: Initial disclosure by Oracle
- 2017-01-27: patched: Fixed in January 2017 Critical Patch Update