Junglewise Threat Intelligence

CVE-2017-3339: Oracle Marketing cross-site vulnerability in User Interface

CVE-2017-3339 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Marketing. Vendors: Oracle.

Executive brief

A vulnerability exists in the User Interface of Oracle Marketing, a component of the Oracle E-Business Suite used for managing marketing campaigns and customer data. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive marketing information or modify existing records. Successful exploitation requires a legitimate user to perform a specific action, such as clicking a malicious link, and could potentially allow the attacker to impact other connected business systems.

Technical details

This vulnerability in Oracle Marketing (part of Oracle E-Business Suite) affects the User Interface subcomponent. It is an unauthenticated, network-based attack vector via HTTP that requires human interaction (UI:R) from a person other than the attacker. The vulnerability has a 'Changed' scope (S:C), meaning an exploit can impact components beyond the Oracle Marketing application itself. Attackers can achieve high confidentiality impact and low integrity impact, resulting in unauthorized access to or modification of critical marketing data. The issue is addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle Marketing 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats