Junglewise Threat Intelligence

CVE-2017-3281: Oracle E-Business Suite data manipulation in Partner Management UI

CVE-2017-3281 · Severity: medium · CVSS 4.7 · Published 2017-01-27

Vendors: Oracle.

Executive brief

A vulnerability exists in the User Interface of Oracle Partner Management, a component of the Oracle E-Business Suite used by organizations to manage business partner relationships. An attacker could trick a legitimate user into performing an action that allows the attacker to modify, insert, or delete certain data within the system. This could lead to unauthorized changes in partner records or business data, potentially impacting other integrated Oracle products.

Technical details

A vulnerability in the User Interface subcomponent of Oracle Partner Management (Oracle E-Business Suite) allows unauthenticated attackers to compromise the system via HTTP. The vulnerability is characterized by a CVSS:3.0 vector indicating a requirement for user interaction (UI:R) and a scope change (S:C), which is often associated with Cross-Site Scripting (XSS) or similar UI-based injection flaws. An attacker can achieve unauthorized update, insert, or delete access to a subset of data. While the flaw resides in Partner Management, the scope change suggests it may be used to impact other products within the E-Business Suite environment. Affected versions include 12.1.1-12.1.3 and 12.2.3-12.2.6.

Affected products

  • Oracle E-Business Suite Partner Management 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: advisory: Initial disclosure by Oracle

References

Related threats