Executive brief
A vulnerability exists in the User Interface of Oracle E-Business Suite's Installed Base component, which is used by organizations to track and manage product lifecycles and customer assets. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify records, potentially leading to data theft or operational disruption. Successful exploitation requires a legitimate user to interact with a malicious link or page, and the impact may extend beyond the Installed Base component to other integrated Oracle products.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Installed Base within Oracle E-Business Suite versions 12.1.1, 12.1.2, and 12.1.3. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the system. The attack requires human interaction from a person other than the attacker (likely a Cross-Site Scripting or similar UI-based injection attack). A successful exploit can lead to unauthorized access to all accessible data or the ability to update, insert, or delete specific records. Notably, the vulnerability has a 'Changed' scope (S:C), meaning an attack on this component can impact other security domains or products within the Oracle ecosystem. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle E-Business Suite Installed Base 12.1.1, 12.1.2, 12.1.3
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-27: patched: Addressed in Oracle January 2017 Critical Patch Update