Executive brief
A vulnerability exists in the patching subcomponent of the Oracle Application Object Library, which is a core part of the Oracle E-Business Suite used for managing business applications. A high-privileged user with access to the underlying server infrastructure could exploit this flaw to gain unauthorized access to sensitive business data. This could result in the unauthorized creation, modification, or deletion of critical corporate information.
Technical details
This vulnerability affects the Patching subcomponent of the Oracle Application Object Library within Oracle E-Business Suite versions 12.1.3 through 12.2.6. It is classified as an 'easily exploitable' flaw that requires high-privileged local access to the infrastructure where the library executes. An attacker with these privileges can bypass security controls to perform unauthorized creation, deletion, or modification of all data accessible to the Application Object Library. The vulnerability primarily impacts confidentiality and integrity, with a CVSS v3.0 base score of 6.0. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle Application Object Library 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-17: patched: Addressed in Oracle January 2017 Critical Patch Update