Junglewise Threat Intelligence

CVE-2017-3349: Oracle Marketing vulnerability in User Interface

CVE-2017-3349 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Marketing. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Marketing component of the Oracle E-Business Suite, which is used by organizations to manage marketing campaigns and customer data. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive marketing information or modify existing data. Successful exploitation requires a legitimate user to interact with a malicious link or page, potentially allowing the attacker to compromise the application and impact connected systems.

Technical details

This vulnerability in the Oracle Marketing User Interface (part of Oracle E-Business Suite) is characterized by a CVSS 3.0 score of 8.2. It is an unauthenticated, network-based attack vector via HTTP that requires human interaction (UI:R) from a person other than the attacker. The vulnerability has a 'Changed' scope (S:C), meaning an exploit can impact components beyond the Oracle Marketing application itself. Successful exploitation can result in unauthorized read access to all accessible data (Confidentiality: High) and unauthorized update, insert, or delete access to some data (Integrity: Low). The issue affects versions 12.1.1 through 12.2.6 and was addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle Marketing 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats