Junglewise Threat Intelligence

CVE-2017-3303: Oracle E-Business Suite XML Gateway data compromise in Oracle Transport Agent

CVE-2017-3303 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Xml Gateway. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle XML Gateway component of Oracle E-Business Suite, which is used for electronic data exchange between business applications. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify existing records. Successful exploitation requires a legitimate user to perform an action, such as clicking a link, and could allow the attacker to impact other connected systems beyond the XML Gateway itself.

Technical details

A vulnerability in the Oracle Transport Agent subcomponent of Oracle XML Gateway allows an unauthenticated attacker with network access via HTTP to compromise the system. The vulnerability is characterized by a CVSS 3.0 vector of AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N, indicating that while it is easily exploitable over the network, it requires human interaction from a person other than the attacker. Successful exploitation can lead to unauthorized access to all XML Gateway data and unauthorized modification (update, insert, or delete) of a subset of that data. Due to the 'Scope: Changed' (S:C) nature of the vulnerability, an attack on the XML Gateway may significantly impact additional products within the Oracle E-Business Suite environment. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle E-Business Suite (XML Gateway) 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update January 2017 released

References

Related threats