Executive brief
Oracle Service Fulfillment Manager, a component of the Oracle E-Business Suite used for managing service orders and provisioning, contains a security vulnerability in its user interface. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify existing records. Successful exploitation requires a legitimate user to interact with a malicious link or page, which could then allow the attacker to compromise the system and potentially impact other integrated business applications.
Technical details
This vulnerability exists in the User Interface subcomponent of Oracle Service Fulfillment Manager within Oracle E-Business Suite. It is classified as an 'easily exploitable' flaw that can be triggered by an unauthenticated attacker over the network via HTTP. The exploit requires human interaction from a person other than the attacker (UI:R), and the 'Scope' is changed (S:C), suggesting it may be a Cross-Site Scripting (XSS) or similar injection vulnerability that allows an attacker to impact components beyond the immediate application. Successful exploitation can result in high confidentiality impact (unauthorized access to all accessible data) and low integrity impact (unauthorized update or delete access to some data). Affected versions include 12.1.1 through 12.2.6.
Affected products
- Oracle Service Fulfillment Manager 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update (CPU) January 2017