Junglewise Threat Intelligence

CVE-2017-3354: Oracle Marketing vulnerability in User Interface

CVE-2017-3354 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Marketing. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Marketing component of the Oracle E-Business Suite, which is used by organizations to manage marketing campaigns and customer data. An attacker could exploit this flaw to gain unauthorized access to sensitive marketing information or modify existing records. This attack requires a legitimate user to perform a specific action, such as clicking a malicious link, and could potentially allow the attacker to impact other connected business systems.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Marketing within Oracle E-Business Suite. It is an unauthenticated, network-based attack vector via HTTP that requires human interaction (UI:R) from a person other than the attacker. The vulnerability has a 'Changed' scope (S:C), meaning a successful exploit can impact components beyond the Oracle Marketing application itself. Attackers can achieve high confidentiality impact, gaining full access to all accessible data, and partial integrity impact through unauthorized updates or deletions. The issue is addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle Marketing 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: advisory: Initial publication of CVE-2017-3354
  • 2017-01-27: patched: Fixed in Oracle Critical Patch Update (CPU) January 2017

References

Related threats