Executive brief
A vulnerability exists in the User Interface of Oracle Marketing, a component of the Oracle E-Business Suite used for managing marketing campaigns and customer data. An unauthenticated attacker can exploit this flaw over the network, provided they can trick a legitimate user into performing a specific action. If successful, the attacker could gain unauthorized access to sensitive marketing data or modify and delete records, potentially impacting other integrated business systems.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Marketing within Oracle E-Business Suite. It is classified as easily exploitable via the HTTP protocol by an unauthenticated remote attacker. Exploitation requires human interaction (User Interaction: Required) from a person other than the attacker. The vulnerability has a 'Changed' scope, meaning a successful attack on Oracle Marketing can impact other components or products within the E-Business Suite. The impact includes high confidentiality loss (unauthorized access to all accessible data) and partial integrity loss (unauthorized update, insert, or delete capabilities). Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle Marketing 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update published