Executive brief
A vulnerability exists in the Oracle Marketing component of the Oracle E-Business Suite, which is used by organizations to manage marketing campaigns and customer data. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive marketing information or modify existing data. Successful exploitation requires a legitimate user to perform a specific action, such as clicking a malicious link, and could potentially allow the attacker to impact other connected systems.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Marketing within Oracle E-Business Suite. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the application. The attack requires human interaction from a person other than the attacker (User Interaction: Required) and features a Scope change, meaning the impact can extend beyond Oracle Marketing to other products. Successful exploitation can result in unauthorized read access to all Oracle Marketing data and unauthorized update, insert, or delete access to a subset of that data. Affected versions include 12.1.1-12.1.3 and 12.2.3-12.2.6.
Affected products
- Oracle Marketing 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory