Executive brief
A vulnerability exists in the user interface of Oracle's Service Fulfillment Manager, a tool used by businesses to manage and automate service orders. An attacker could trick a legitimate user into performing an action that allows the attacker to view or modify sensitive business data. This could lead to unauthorized access to critical information or the alteration of existing records within the system.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Service Fulfillment Manager within the Oracle E-Business Suite. It is an unauthenticated, network-based attack vector via HTTP that requires human interaction (User Interaction: Required) from a person other than the attacker. The vulnerability has a 'Changed' scope (S:C), meaning an exploit can impact components beyond the Service Fulfillment Manager itself. Successful exploitation can result in unauthorized read access to all accessible data and unauthorized update, insert, or delete access to a subset of that data. The vulnerability was addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle E-Business Suite Service Fulfillment Manager 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: advisory: Initial NVD publication date
- 2017-01-17: patched: Addressed in Oracle January 2017 Critical Patch Update