Executive brief
A vulnerability in Oracle FLEXCUBE Direct Banking, a platform used by financial institutions for online banking services, could allow an unauthorized person to view sensitive information. To exploit this, an attacker would need to trick a legitimate user into performing a specific action, such as clicking a malicious link. While the primary impact is unauthorized access to a limited set of data, the breach could potentially affect other integrated systems.
Technical details
This vulnerability exists in the Pre-Login subcomponent of Oracle FLEXCUBE Direct Banking (versions 12.0.2 and 12.0.3). It is classified as an information disclosure issue (CWE-200) that is exploitable over the network via HTTP without authentication. A successful exploit requires human interaction from a victim (User Interaction: Required) and results in a 'Changed' scope, meaning the impact can extend beyond the FLEXCUBE application itself. Attackers can achieve unauthorized read access to a subset of data. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle FLEXCUBE Direct Banking 12.0.2, 12.0.3
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update published