Junglewise Threat Intelligence

CVE-2017-3352: Oracle Marketing User Interface unauthorized data access

CVE-2017-3352 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Marketing. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Marketing component of the Oracle E-Business Suite, which is used by organizations to manage marketing campaigns and customer data. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive marketing information or modify existing data. Successful exploitation requires a legitimate user to interact with a malicious link or page, potentially leading to a significant breach of customer information and operational integrity.

Technical details

This vulnerability resides in the User Interface subcomponent of Oracle Marketing within Oracle E-Business Suite. It is classified as an 'Insufficient Information' (NVD-CWE-noinfo) issue, but the CVSS vector (UI:R and S:C) strongly suggests a Cross-Site Scripting (XSS) or similar client-side injection flaw that can impact components beyond the initial scope. An unauthenticated attacker can exploit this over HTTP by inducing a user to perform an action (human interaction). Successful exploitation can result in high confidentiality impact (unauthorized access to all Oracle Marketing data) and partial integrity impact (unauthorized update/delete access). The vulnerability affects versions 12.1.1 through 12.2.6 and was addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle Marketing 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update (CPU) January 2017 released

References

Related threats