Junglewise Threat Intelligence

CVE-2017-3333: Oracle E-Business Suite vulnerability in Oracle Marketing User Interface

CVE-2017-3333 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Marketing. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Marketing component of the Oracle E-Business Suite, which is used by organizations to manage marketing campaigns and customer data. An attacker could exploit this flaw to gain unauthorized access to sensitive business information or modify marketing data. This attack requires a legitimate user to perform an action, such as clicking a malicious link, and could potentially allow the attacker to impact other connected business systems.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Marketing within Oracle E-Business Suite. It is an unauthenticated, network-based attack vector (HTTP) that requires user interaction (UI:R) to succeed. The vulnerability is characterized by a 'Scope' change (S:C), meaning an exploit can impact components beyond the immediate Oracle Marketing environment. Successful exploitation can result in unauthorized read access to all Oracle Marketing data and unauthorized update, insert, or delete access to a subset of that data. Affected versions include 12.1.1-12.1.3 and 12.2.3-12.2.6. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Marketing 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats