Junglewise Threat Intelligence

CVE-2017-3343: Oracle E-Business Suite Oracle Marketing data compromise in User Interface

CVE-2017-3343 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Marketing. Vendors: Oracle.

Executive brief

A vulnerability exists in the User Interface of Oracle Marketing, a component of the Oracle E-Business Suite used for managing marketing campaigns and customer data. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive business information or modify marketing data. Successful exploitation requires a legitimate user to interact with a malicious link or page, which could lead to a significant breach of data confidentiality and integrity across the platform.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Marketing within Oracle E-Business Suite. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the application. The attack requires human interaction from a person other than the attacker (UI:R) and has a 'Changed' scope (S:C), meaning the impact can extend beyond the Oracle Marketing component to other parts of the E-Business Suite. Exploitation can result in unauthorized read access to all accessible data and unauthorized update, insert, or delete access to a subset of that data. Affected versions include 12.1.1-12.1.3 and 12.2.3-12.2.6.

Affected products

  • Oracle Marketing 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update (CPU) January 2017

References

Related threats