Junglewise Threat Intelligence

CVE-2017-3335: Oracle Marketing vulnerability in User Interface

CVE-2017-3335 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Marketing. Vendors: Oracle.

Executive brief

A vulnerability exists in the user interface of Oracle Marketing, a component of the Oracle E-Business Suite used for managing marketing campaigns and customer data. An attacker could exploit this flaw to gain unauthorized access to sensitive marketing information or modify existing data. Successful exploitation requires a legitimate user to perform a specific action, such as clicking a malicious link, and could potentially allow the attacker to impact other connected systems.

Technical details

This vulnerability in Oracle Marketing (part of Oracle E-Business Suite) is located in the User Interface subcomponent. It is an unauthenticated, network-based attack vector via HTTP that requires human interaction (UI:R) from a person other than the attacker. The vulnerability has a 'Changed' scope (S:C), meaning an exploit can impact components beyond the immediate Oracle Marketing environment. Successful exploitation can result in unauthorized high-impact confidentiality loss and low-impact integrity loss, allowing for the reading, insertion, or deletion of sensitive data. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Marketing 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: NVD publication date
  • 2017-01-17: patched: Oracle January 2017 Critical Patch Update

References

Related threats