Junglewise Threat Intelligence

CVE-2017-3353: Oracle Marketing vulnerability in User Interface

CVE-2017-3353 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Marketing. Vendors: Oracle.

Executive brief

A vulnerability exists in the user interface of Oracle Marketing, a component of the Oracle E-Business Suite used by organizations to manage marketing campaigns and customer data. An attacker could trick a legitimate user into performing an action that allows the attacker to view or modify sensitive marketing information. This could lead to the unauthorized disclosure of customer lists or the corruption of marketing data, potentially impacting other integrated business systems.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Marketing within Oracle E-Business Suite versions 12.1.x and 12.2.x. It is an unauthenticated, network-based attack vector (HTTP) that requires human interaction from a person other than the attacker (UI:R). The vulnerability has a 'Changed' scope (S:C), meaning an exploit can impact components beyond the Oracle Marketing subcomponent itself. Successful exploitation can result in unauthorized read access to all Oracle Marketing data and unauthorized update, insert, or delete access to a subset of that data. The issue was addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle Marketing 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats