Executive brief
A vulnerability exists in the Resources Module of Oracle E-Business Suite's Common Applications component. This flaw allows an unauthenticated remote attacker to potentially gain full access to sensitive business data or modify records. Exploitation requires a legitimate user to perform an action, such as clicking a malicious link, and the impact can extend beyond the immediate application to other integrated business systems.
Technical details
This vulnerability affects the Resources Module subcomponent of Oracle Common Applications within the Oracle E-Business Suite. It is an unauthenticated, network-based attack vector via HTTP that requires user interaction (UI:R) to succeed. The vulnerability has a 'Changed' scope (S:C), meaning a successful exploit can impact components beyond the immediate security scope of the Oracle Common Applications. Attackers can achieve unauthorized access to all accessible data (Confidentiality) and perform unauthorized updates, inserts, or deletes on a subset of data (Integrity). Affected versions include 12.1.1-12.1.3 and 12.2.3-12.2.6. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle Common Applications 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update published