Executive brief
A vulnerability exists in the user interface of Oracle E-Business Suite's Partner Management module, which is used by organizations to manage business partner relationships. An attacker could trick a legitimate user into performing an action that allows the attacker to modify, insert, or delete certain partner-related data. While the vulnerability is contained within the Partner Management component, an exploit could potentially impact the integrity of data in other connected systems.
Technical details
This vulnerability is classified as improper input validation (CWE-20) within the User Interface subcomponent of Oracle Partner Management. It is exploitable by an unauthenticated attacker with network access via HTTP, though it requires human interaction from a person other than the attacker (typically a victim user clicking a malicious link). The vulnerability has a 'Scope' impact, meaning a successful exploit can affect components beyond the immediate Partner Management module. Attackers can achieve unauthorized update, insert, or delete access to a subset of data accessible to the Partner Management component. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle E-Business Suite Partner Management 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update published