Junglewise Threat Intelligence

CVE-2017-3359: Oracle Customer Intelligence unauthorized data access in User Interface

CVE-2017-3359 · Severity: high · CVSS 8.2 · Published 2017-01-27

Vendors: Oracle.

Executive brief

A vulnerability exists in the user interface of Oracle Customer Intelligence, a component of the Oracle E-Business Suite used for analyzing customer data. An attacker could exploit this flaw to gain unauthorized access to sensitive customer information or modify existing records. This attack requires a legitimate user to perform an action, such as clicking a malicious link, and could potentially allow the attacker to impact other connected Oracle systems.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Customer Intelligence within Oracle E-Business Suite versions 12.1.1, 12.1.2, and 12.1.3. It is an unauthenticated, network-based attack vector via HTTP that requires user interaction (UI:R) from a person other than the attacker. The vulnerability has a 'Changed' scope (S:C), meaning an exploit can impact components beyond the immediate Customer Intelligence environment. Successful exploitation can result in high confidentiality impact (unauthorized access to all data) and low integrity impact (unauthorized update, insert, or delete access to some data). Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Customer Intelligence 12.1.1, 12.1.2, 12.1.3

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-27: patched: Addressed in Oracle January 2017 Critical Patch Update

References

Related threats