Executive brief
A vulnerability exists in the Oracle Marketing component of the Oracle E-Business Suite, which is used by organizations to manage marketing campaigns and customer data. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive marketing information or modify existing records. Successful exploitation requires a legitimate user to interact with a malicious link or page, potentially allowing the attacker to compromise the application and impact connected systems.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Marketing within Oracle E-Business Suite. It is classified as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the application. The attack requires human interaction from a person other than the attacker (UI:R) and has a 'Changed' scope (S:C), meaning the impact can extend beyond the Oracle Marketing component to other parts of the E-Business Suite. Exploitation can result in unauthorized high-impact confidentiality breaches and low-impact integrity violations, such as unauthorized data updates or deletions. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle Marketing 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update published