Junglewise Threat Intelligence

CVE-2017-3282: Oracle Partner Management unauthorized data modification in User Interface

CVE-2017-3282 · Severity: medium · CVSS 4.7 · Published 2017-01-27

Technologies: Oracle Partner Management. Vendors: Oracle.

Executive brief

A vulnerability exists in the user interface of Oracle Partner Management, a component of the Oracle E-Business Suite used for managing business partner relationships. An unauthenticated attacker could trick a legitimate user into performing an action that allows the attacker to modify, insert, or delete certain business data. While the primary impact is on partner management data, the breach could potentially affect other integrated business systems.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Partner Management within Oracle E-Business Suite. It is classified as an integrity-impacting flaw that is remotely exploitable via HTTP without authentication, though it requires user interaction (UI:R) to succeed. The vulnerability has a 'Scope' impact (S:C), meaning an exploit can affect components beyond the immediate Partner Management module. Successful exploitation allows an attacker to perform unauthorized update, insert, or delete operations on accessible data. Affected versions include 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6.

Affected products

  • Oracle Partner Management 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-17: patched: Oracle Critical Patch Update (CPU) released

References

Related threats