Junglewise Threat Intelligence

CVE-2017-3280: Oracle E-Business Suite improper input validation in Partner Management UI

CVE-2017-3280 · Severity: medium · CVSS 4.7 · Published 2017-01-27

Technologies: Oracle Partner Management. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Partner Management component of the Oracle E-Business Suite, which is used by organizations to manage business partner relationships. An unauthenticated attacker could trick a legitimate user into performing an action that allows the attacker to modify, insert, or delete certain business data. While the primary impact is on partner data integrity, the exploit could potentially affect other integrated business systems.

Technical details

This vulnerability is classified as improper input validation (CWE-20) within the User Interface subcomponent of Oracle Partner Management. It is remotely exploitable via HTTP without authentication, though it requires user interaction (UI:R) to succeed. The vulnerability has a 'Changed' scope (S:C), meaning an exploit can impact components beyond the immediate Partner Management module. Successful exploitation allows an attacker to perform unauthorized updates, insertions, or deletions of data, impacting the integrity of the system. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Partner Management 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: advisory: Initial publication of the vulnerability advisory
  • 2017-01-27: patched: Fix released in Oracle Critical Patch Update

References

Related threats