Junglewise Threat Intelligence

CVE-2017-3277: Oracle E-Business Suite Information Disclosure in Oracle Applications Manager

CVE-2017-3277 · Severity: medium · CVSS 4.9 · Published 2017-01-27

Technologies: Oracle Applications Manager, Oracle E-Business Suite. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Applications Manager component of the Oracle E-Business Suite, which is used by organizations to manage enterprise resources and applications. A high-privileged attacker could exploit this flaw to gain unauthorized access to sensitive business data. This could lead to a significant breach of confidentiality regarding critical corporate information managed within the suite.

Technical details

This vulnerability is classified as an information disclosure (CWE-200) within the OAM Client subcomponent of Oracle Applications Manager. It is easily exploitable by a high-privileged attacker with network access via HTTP. The flaw allows an attacker to bypass intended confidentiality protections to access critical data or all data accessible to the Oracle Applications Manager. The vulnerability affects Oracle E-Business Suite versions 12.1.3 and 12.2.3 through 12.2.6. Oracle addressed this issue in the January 2017 Critical Patch Update.

Affected products

  • Oracle E-Business Suite (Oracle Applications Manager) 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: NVD publication date
  • 2017-01-17: patched: Oracle January 2017 Critical Patch Update

References

Related threats