Executive brief
A vulnerability exists in the Role Summary component of Oracle E-Business Suite's Common Applications. This flaw allows an unauthenticated remote attacker to potentially gain unauthorized access to sensitive business data or modify existing records. Exploitation requires a legitimate user to perform a specific action, such as clicking a malicious link, and could lead to a significant breach of data confidentiality and integrity across the suite.
Technical details
This vulnerability affects the Role Summary subcomponent of Oracle Common Applications within the Oracle E-Business Suite. It is an unauthenticated, network-based attack via HTTP that requires user interaction (UI:R) to succeed. The vulnerability has a 'Changed' scope (S:C), meaning an exploit can impact components beyond the immediate Role Summary subcomponent. Attackers can achieve high confidentiality impact, potentially accessing all data within the application, and low integrity impact, allowing for unauthorized updates or deletions of certain data. Affected versions include 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle Common Applications 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update published