Junglewise Threat Intelligence

CVE-2017-3363: Oracle Knowledge Management vulnerability in User Interface

CVE-2017-3363 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Knowledge Management. Vendors: Oracle.

Executive brief

A vulnerability exists in the User Interface of Oracle Knowledge Management, a component of the Oracle E-Business Suite used for managing corporate information and support resources. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive data or modify existing records. Successful exploitation requires a legitimate user to interact with a malicious link or page, which could lead to a significant breach of data integrity and confidentiality across the platform.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Knowledge Management (versions 12.1.1, 12.1.2, and 12.1.3). It is classified as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the application. The exploit requires human interaction from a person other than the attacker (UI:R) and has a 'Changed' scope (S:C), meaning the impact can extend beyond the Knowledge Management component to other parts of the Oracle E-Business Suite. Attackers can achieve unauthorized access to critical data and perform unauthorized updates or deletions. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Knowledge Management 12.1.1, 12.1.2, 12.1.3

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-17: patched: Released as part of Oracle Critical Patch Update (CPU) January 2017

References

Related threats