Junglewise Threat Intelligence

CVE-2017-3246: Oracle E-Business Suite data compromise in Application Object Library

CVE-2017-3246 · Severity: medium · CVSS 6 · Published 2017-01-27

Technologies: Oracle Application Object Library. Vendors: Oracle.

Executive brief

A vulnerability exists in the patching subcomponent of the Oracle Application Object Library, which is a core part of the Oracle E-Business Suite used for managing business applications. A high-privileged user with access to the underlying server infrastructure could exploit this flaw to gain unauthorized access to sensitive business data. This could result in the unauthorized creation, modification, or deletion of critical corporate information.

Technical details

This vulnerability affects the Patching subcomponent of the Oracle Application Object Library within Oracle E-Business Suite versions 12.1.3 through 12.2.6. It is classified as an 'easily exploitable' flaw that requires high-privileged local access to the infrastructure where the library executes. An attacker with these privileges can bypass security controls to perform unauthorized creation, deletion, or modification of all data accessible to the Application Object Library. The vulnerability primarily impacts confidentiality and integrity, with a CVSS v3.0 base score of 6.0. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Application Object Library 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-17: patched: Addressed in Oracle January 2017 Critical Patch Update

References

Related threats