Junglewise Threat Intelligence

CVE-2017-3274: Oracle Email Center unauthorized access in User Interface

CVE-2017-3274 · Severity: high · CVSS 8.2 · Published 2017-01-27

Vendors: Oracle.

Executive brief

Oracle Email Center, a component of the Oracle E-Business Suite used for managing high-volume email communications, contains a security vulnerability in its user interface. An attacker could exploit this to gain unauthorized access to sensitive data or modify information within the system. This attack requires a legitimate user to perform an action, such as clicking a malicious link, and could potentially impact other connected business systems.

Technical details

A vulnerability exists in the User Interface subcomponent of Oracle Email Center (part of Oracle E-Business Suite). The flaw is easily exploitable by an unauthenticated remote attacker via HTTP. Exploitation requires human interaction from a person other than the attacker (UI:R). The vulnerability has a 'Changed' scope (S:C), meaning a successful attack can impact products beyond Oracle Email Center. Impact includes unauthorized access to all accessible data (Confidentiality: High) and unauthorized update, insert, or delete access to some data (Integrity: Low). Affected versions include 12.1.1 through 12.2.6.

Affected products

  • Oracle Email Center 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats