Executive brief
A vulnerability exists in the User Interface of Oracle Marketing, a component of the Oracle E-Business Suite used for managing marketing campaigns and customer data. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive marketing data or modify existing records. Successful exploitation requires a legitimate user to interact with a malicious link or page, which could lead to a significant breach of confidentiality and data integrity across the platform.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Marketing within Oracle E-Business Suite. It is classified as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the application. The attack requires human interaction (User Interaction: Required) from a person other than the attacker, suggesting a Cross-Site Scripting (XSS) or similar UI-based injection vector. Successful exploitation can result in unauthorized access to critical data (Confidentiality) and unauthorized update, insert, or delete access to some data (Integrity). The vulnerability also features 'Scope: Changed,' indicating that an attack on Oracle Marketing could impact other integrated products within the E-Business Suite.
Affected products
- Oracle Marketing 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update (CPU) January 2017