Junglewise Threat Intelligence

CVE-2017-3327: Oracle E-Business Suite vulnerability in Common Applications Resources Module

CVE-2017-3327 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Common Applications. Vendors: Oracle.

Executive brief

A vulnerability exists in the Resources Module of Oracle E-Business Suite's Common Applications component. This flaw allows an unauthenticated attacker to gain unauthorized access to sensitive business data or modify existing records. Exploitation requires a legitimate user to perform a specific action, such as clicking a malicious link, and can lead to a significant breach of data confidentiality and integrity across the suite.

Technical details

This vulnerability affects the Resources Module subcomponent of Oracle Common Applications in Oracle E-Business Suite. It is classified as an 'easily exploitable' flaw that allows an unauthenticated attacker with network access via HTTP to compromise the system. The attack requires user interaction (UI:R) from a person other than the attacker. The vulnerability has a 'Changed' scope (S:C), meaning an exploit can impact components beyond the immediate Resources Module. Successful exploitation can lead to unauthorized read access to all data or unauthorized update/delete access to a subset of data. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Common Applications 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-27: patched: Addressed in Oracle January 2017 Critical Patch Update

References

Related threats