Junglewise Threat Intelligence

CVE-2017-3297: Oracle FLEXCUBE Direct Banking information disclosure in Framework

CVE-2017-3297 · Severity: medium · CVSS 5.3 · Published 2017-01-27

Vendors: Oracle.

Executive brief

A vulnerability in the Oracle FLEXCUBE Direct Banking framework could allow an unauthorized user to access sensitive financial data. FLEXCUBE is a core banking platform used by financial institutions to manage digital banking operations. If exploited, this flaw could lead to the exposure of critical customer information or complete access to all data managed by the banking application.

Technical details

This vulnerability exists in the Framework subcomponent of Oracle FLEXCUBE Direct Banking (versions 12.0.2 and 12.0.3). It is classified as an information disclosure issue that allows a low-privileged attacker with network access via HTTP to compromise the system. The attack is characterized as difficult to exploit (High Attack Complexity), likely due to specific environmental conditions or timing required for a successful breach. If successful, the attacker can gain unauthorized access to critical data or complete access to all data accessible by the FLEXCUBE Direct Banking component. Oracle addressed this issue in the January 2017 Critical Patch Update.

Affected products

  • Oracle FLEXCUBE Direct Banking 12.0.2, 12.0.3

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-27: patched: Addressed in Oracle January 2017 Critical Patch Update

References

Related threats