Junglewise Threat Intelligence

CVE-2017-3351: Oracle Marketing vulnerability in User Interface

CVE-2017-3351 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Marketing. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Marketing component of the Oracle E-Business Suite, which is used by organizations to manage marketing campaigns and customer data. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive marketing information or modify existing records. Successful exploitation requires a legitimate user to interact with a malicious link or page, potentially allowing the attacker to compromise the marketing platform and impact connected business systems.

Technical details

A vulnerability in the User Interface subcomponent of Oracle Marketing (part of Oracle E-Business Suite) allows an unauthenticated remote attacker to compromise the application via HTTP. The flaw is characterized by a 'Scope' change in CVSS metrics, suggesting it may be a Cross-Site Scripting (XSS) or similar injection vulnerability that allows an attacker to impact components beyond the immediate marketing module. Exploitation requires human interaction from a person other than the attacker (User Interaction: Required). Successful attacks can result in unauthorized read access to all Oracle Marketing data and unauthorized update, insert, or delete access to a subset of that data. Affected versions include 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6.

Affected products

  • Oracle Marketing 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-17: patched: Addressed in Oracle Critical Patch Update (CPU) January 2017

References

Related threats