Executive brief
A vulnerability exists in the Oracle Leads Management component of the Oracle E-Business Suite, which is used by organizations to manage sales prospects and marketing data. An attacker could exploit this flaw to gain unauthorized access to sensitive business leads or modify existing records. This attack requires a legitimate user to perform a specific action, such as clicking a malicious link, and could potentially allow the attacker to impact other connected business systems.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Leads Management in Oracle E-Business Suite versions 12.1.1 through 12.1.3. It is an unauthenticated, network-based attack vector via HTTP. The exploit requires human interaction (UI:R) from a person other than the attacker. Successful exploitation can result in a 'Scope' change (S:C), meaning the impact can extend beyond the Leads Management component to other products. Attackers can achieve unauthorized access to critical data (Confidentiality: High) and unauthorized update or delete access to some data (Integrity: Low). Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle Leads Management 12.1.1, 12.1.2, 12.1.3
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-17: patched: Addressed in Oracle January 2017 Critical Patch Update