Executive brief
A vulnerability exists in the User Interface of Oracle Marketing, a component of the Oracle E-Business Suite used for managing marketing campaigns and customer data. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive marketing information or modify existing data. Successful exploitation requires a legitimate user to interact with a malicious link or page, which could lead to a significant breach of data confidentiality and integrity across the marketing platform.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Marketing within Oracle E-Business Suite. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the application. The exploit requires human interaction from a person other than the attacker (typically a Cross-Site Scripting or similar UI-based attack). A successful attack can result in unauthorized access to critical data, complete access to all Oracle Marketing data, and unauthorized modification (update, insert, or delete) of certain records. The vulnerability has a 'Changed' scope, meaning it may impact components beyond Oracle Marketing itself. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle Marketing 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update published