Junglewise Threat Intelligence

CVE-2017-3341: Oracle Marketing vulnerability in User Interface

CVE-2017-3341 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Marketing. Vendors: Oracle.

Executive brief

A vulnerability exists in the User Interface of Oracle Marketing, a component of the Oracle E-Business Suite used for managing marketing campaigns and customer data. An attacker could exploit this to gain unauthorized access to sensitive business information or modify marketing data. Successful exploitation requires a legitimate user to perform an action, such as clicking a malicious link, and could potentially allow the attacker to impact other connected systems.

Technical details

This vulnerability in the Oracle Marketing component of Oracle E-Business Suite affects the User Interface subcomponent. It is an unauthenticated, network-based attack vector via HTTP that requires user interaction (CVSS UI:R). The vulnerability is characterized by a 'Scope' change (CVSS S:C), meaning an exploit can impact components beyond the immediate Oracle Marketing environment. Attackers can achieve high confidentiality impact and partial integrity impact, allowing for the unauthorized reading, insertion, or deletion of marketing data. The issue is addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle Marketing 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats