Executive brief
A vulnerability exists in the User Interface of Oracle Marketing, a component of the Oracle E-Business Suite used for managing marketing campaigns and customer data. An unauthenticated attacker can exploit this flaw to gain unauthorized access to sensitive marketing information or modify existing records. This attack requires a legitimate user to interact with a malicious link or page, and the impact may extend beyond the marketing module to other connected business systems.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Marketing within Oracle E-Business Suite. It is classified as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the application. The exploit requires human interaction from a person other than the attacker (UI:R) and has a 'Changed' scope (S:C), meaning the impact can extend to other components or products. Successful exploitation can result in unauthorized read access to all Oracle Marketing data and unauthorized update, insert, or delete access to a subset of that data. The vulnerability is addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle Marketing 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: advisory: Initial publication of CVE-2017-3340
- 2017-01-27: patched: Fixed in Oracle Critical Patch Update (CPU) January 2017