Executive brief
A vulnerability exists in the User Interface of Oracle Knowledge Management, a component of the Oracle E-Business Suite used for managing corporate information and support resources. An attacker could exploit this to gain unauthorized access to sensitive data or modify existing records, potentially compromising the integrity of business information. Successful exploitation requires a legitimate user to interact with a malicious link or page, but the impact can extend beyond the Knowledge Management module to other parts of the E-Business Suite.
Technical details
This vulnerability resides in the User Interface subcomponent of Oracle Knowledge Management within Oracle E-Business Suite versions 12.1.1 through 12.1.3. It is an unauthenticated, network-based attack vector via HTTP that requires user interaction (UI:R) from a person other than the attacker. The vulnerability has a 'Changed' scope (S:C), meaning an exploit can impact components beyond the immediate Knowledge Management environment. Attackers can achieve high confidentiality impact (unauthorized access to all accessible data) and low integrity impact (unauthorized update, insert, or delete access to some data). Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle Knowledge Management 12.1.1, 12.1.2, 12.1.3
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-17: patched: Addressed in Oracle January 2017 Critical Patch Update