Junglewise Threat Intelligence

CVE-2017-3278: Oracle One-to-One Fulfillment security bypass in Request Confirmation

CVE-2017-3278 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle One-To-One Fulfillment. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle One-to-One Fulfillment component of the Oracle E-Business Suite, which is used by organizations to manage high-volume personalized communications. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify existing records. Successful exploitation requires a legitimate user to perform a specific action, such as clicking a malicious link, and could potentially allow the attacker to impact other connected systems beyond the fulfillment module.

Technical details

This vulnerability affects the Request Confirmation subcomponent of Oracle One-to-One Fulfillment (version 12.1.3) within the Oracle E-Business Suite. It is classified as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the component. The attack requires human interaction from a person other than the attacker (User Interaction: Required) and results in a Scope change, meaning the security impact can extend to products beyond the immediate fulfillment component. Successful exploitation can lead to unauthorized read access to all accessible data (Confidentiality: High) and unauthorized update or delete access to some data (Integrity: Low). Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle One-to-One Fulfillment 12.1.3

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats