Junglewise Threat Intelligence

CVE-2017-3357: Oracle Marketing vulnerability in User Interface

CVE-2017-3357 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Marketing. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Marketing component of the Oracle E-Business Suite, which is used by organizations to manage marketing campaigns and customer data. An attacker could exploit this flaw to gain unauthorized access to sensitive marketing information or modify existing data. This attack requires a legitimate user to interact with a malicious link or page, and the impact could potentially spread to other connected Oracle products.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Marketing within Oracle E-Business Suite. It is an unauthenticated, network-based attack vector via HTTP that requires human interaction (User Interaction: Required) from a person other than the attacker. The vulnerability is characterized by a 'Scope: Changed' metric, meaning an exploit can impact components beyond the Oracle Marketing application itself. Successful exploitation can result in complete confidentiality loss of accessible data and partial integrity loss through unauthorized updates or deletions. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Marketing 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats