Junglewise Threat Intelligence

CVE-2017-3245: Oracle FLEXCUBE Direct Banking information disclosure in Pre-Login

CVE-2017-3245 · Severity: medium · CVSS 4.7 · Published 2017-01-27

Vendors: Oracle.

Executive brief

A vulnerability in Oracle FLEXCUBE Direct Banking, a platform used by financial institutions for online banking services, could allow an unauthorized person to view sensitive information. To exploit this, an attacker would need to trick a legitimate user into performing a specific action, such as clicking a malicious link. While the primary impact is unauthorized access to a limited set of data, the breach could potentially affect other integrated systems.

Technical details

This vulnerability exists in the Pre-Login subcomponent of Oracle FLEXCUBE Direct Banking (versions 12.0.2 and 12.0.3). It is classified as an information disclosure issue (CWE-200) that is exploitable over the network via HTTP without authentication. A successful exploit requires human interaction from a victim (User Interaction: Required) and results in a 'Changed' scope, meaning the impact can extend beyond the FLEXCUBE application itself. Attackers can achieve unauthorized read access to a subset of data. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle FLEXCUBE Direct Banking 12.0.2, 12.0.3

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats