Junglewise Threat Intelligence

CVE-2017-3358: Oracle Marketing vulnerability in User Interface

CVE-2017-3358 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Marketing. Vendors: Oracle.

Executive brief

A vulnerability exists in the User Interface of Oracle Marketing, a component of the Oracle E-Business Suite used for managing marketing campaigns and customer data. An attacker could exploit this flaw to gain unauthorized access to sensitive business information or modify marketing data. Successful exploitation requires a legitimate user to interact with a malicious link or page, which could lead to a significant breach of data confidentiality and integrity across the platform.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Marketing within Oracle E-Business Suite. It is an unauthenticated, network-based attack vector via HTTP that requires user interaction (UI:R) from someone other than the attacker. The vulnerability has a 'Changed' scope (S:C), meaning an exploit can impact components beyond Oracle Marketing itself. Attackers can achieve high confidentiality impact and low integrity impact, resulting in unauthorized reading of all accessible data and unauthorized modification or deletion of some data. The issue is addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle Marketing 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory
  • 2017-01-27: patched

References

Related threats