Junglewise Threat Intelligence

CVE-2017-3286: Oracle Applications DBA data compromise in Patching subcomponent

CVE-2017-3286 · Severity: medium · CVSS 6 · Published 2017-01-27

Technologies: Oracle Applications Dba. Vendors: Oracle.

Executive brief

A vulnerability exists in the patching subcomponent of Oracle Applications DBA, which is part of the Oracle E-Business Suite used for managing enterprise resources. An attacker with high-level administrative access to the underlying server can exploit this flaw to gain full control over the application's data. This could lead to the unauthorized viewing, modification, or deletion of sensitive business information.

Technical details

This vulnerability affects the Oracle Applications DBA component of the Oracle E-Business Suite, specifically within the Patching subcomponent. It is classified as an 'easily exploitable' flaw that requires the attacker to have high privileges (PR:H) and local logon access (AV:L) to the infrastructure where the component executes. Successful exploitation allows the attacker to bypass security restrictions to create, delete, or modify all data accessible to the Applications DBA. The vulnerability impacts confidentiality and integrity but does not directly affect service availability. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Applications DBA 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: advisory: Initial disclosure by Oracle
  • 2017-01-27: patched: Fix released in Oracle Critical Patch Update

References

Related threats