Junglewise Threat Intelligence

CVE-2017-3296: Oracle Commerce Platform Information Disclosure in Dynamo Application Framework

CVE-2017-3296 · Severity: medium · CVSS 4.3 · Published 2017-01-27

Technologies: Oracle Commerce Platform. Vendors: Oracle.

Executive brief

Oracle Commerce Platform, a suite used for managing large-scale e-commerce operations, contains a security vulnerability in its Dynamo Application Framework. An unauthenticated attacker could trick a legitimate user into performing an action that allows the attacker to view sensitive business data. While the attacker cannot modify data or shut down the system, this could lead to the exposure of private information.

Technical details

An information disclosure vulnerability exists in the Dynamo Application Framework subcomponent of Oracle Commerce Platform (versions 10.0.3.5, 10.2.0.5, and 11.2.0.2). The flaw is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). An unauthenticated attacker can exploit this over the network via HTTP, though the attack requires human interaction from a victim (User Interaction: Required). Successful exploitation allows the attacker to gain unauthorized read access to a subset of data accessible to the platform. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Commerce Platform 10.0.3.5, 10.2.0.5, 11.2.0.2

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle January 2017 Critical Patch Update published

References

Related threats