Junglewise Threat Intelligence

CVE-2017-3314: Oracle FLEXCUBE Universal Banking data manipulation in Core subcomponent

CVE-2017-3314 · Severity: medium · CVSS 6.1 · Published 2017-01-27

Technologies: Oracle Flexcube Universal Banking. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle FLEXCUBE Universal Banking, a core banking platform used by financial institutions to manage retail and corporate banking operations. An unauthenticated attacker could trick a legitimate user into performing an action that allows the attacker to view, modify, or delete sensitive banking data. This could lead to unauthorized financial transactions or the exposure of private customer information.

Technical details

This vulnerability affects the Core subcomponent of Oracle FLEXCUBE Universal Banking versions 12.0.0, 12.1.0, and 12.2.0. It is an unauthenticated, network-based attack delivered via HTTP. The exploit requires human interaction from a person other than the attacker (User Interaction: Required) and has a 'Changed' scope, meaning the impact can extend beyond the FLEXCUBE component itself to other integrated products. Successful exploitation allows for unauthorized read access to a subset of data and unauthorized update, insert, or delete access to some accessible data. The vulnerability was addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle FLEXCUBE Universal Banking 12.0.0, 12.1.0, 12.2.0

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-17: patched: Addressed in Oracle January 2017 Critical Patch Update

References

Related threats