Executive brief
A vulnerability exists in the User Interface of Oracle Customer Intelligence, a component of the Oracle E-Business Suite used for analyzing customer data. An unauthenticated attacker can exploit this flaw by tricking a legitimate user into performing a specific action, such as clicking a malicious link. If successful, the attacker could gain unauthorized access to sensitive customer information or modify data, potentially impacting other integrated business systems.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Customer Intelligence versions 12.1.1, 12.1.2, and 12.1.3. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the application. The exploit requires human interaction from a person other than the attacker (UI interaction). The vulnerability has a 'Changed' scope (S:C), meaning a successful attack can impact products beyond Oracle Customer Intelligence. Impact includes high confidentiality loss (unauthorized access to all accessible data) and low integrity impact (unauthorized update, insert, or delete access to some data).
Affected products
- Oracle Customer Intelligence 12.1.1, 12.1.2, 12.1.3
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-17: patched: Addressed in Oracle Critical Patch Update (CPU) January 2017