Junglewise Threat Intelligence

CVE-2017-3275: Oracle Email Center unauthorized data access in User Interface

CVE-2017-3275 · Severity: high · CVSS 8.2 · Published 2017-01-27

Vendors: Oracle.

Executive brief

Oracle Email Center, a component of the Oracle E-Business Suite used for managing high-volume email communications, contains a security vulnerability in its user interface. An attacker can exploit this flaw to gain unauthorized access to sensitive data or modify information within the system. Successful exploitation requires a legitimate user to perform an action, such as clicking a malicious link, and could potentially allow the attacker to impact other connected business systems.

Technical details

This vulnerability exists in the User Interface subcomponent of Oracle Email Center within Oracle E-Business Suite. It is classified as easily exploitable by an unauthenticated attacker with network access via HTTP. The exploit requires human interaction from a person other than the attacker (UI:R) and has a 'Changed' scope (S:C), meaning a successful attack can impact components beyond the Email Center itself. Attackers can achieve unauthorized read access to all data or unauthorized update/delete access to a subset of data. The vulnerability affects versions 12.1.1 through 12.2.6 and was addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle Email Center 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-27: patched: Addressed in Oracle January 2017 Critical Patch Update

References

Related threats