Junglewise Threat Intelligence

CVE-2017-3364: Oracle Knowledge Management vulnerability in User Interface

CVE-2017-3364 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Knowledge Management. Vendors: Oracle.

Executive brief

A vulnerability in the User Interface of Oracle Knowledge Management allows an unauthenticated attacker to compromise the system via the network. Successful exploitation requires a legitimate user to interact with a malicious link or page, which could lead to the unauthorized viewing, modification, or deletion of sensitive business data. This flaw may also allow attackers to impact other integrated products within the Oracle E-Business Suite.

Technical details

This vulnerability exists in the User Interface subcomponent of Oracle Knowledge Management within Oracle E-Business Suite versions 12.1.1, 12.1.2, and 12.1.3. It is an unauthenticated, network-based attack (HTTP) that requires human interaction from a victim (UI:R) and results in a Scope change (S:C). While the specific CWE is not provided by the vendor, the CVSS vector suggests a Cross-Site Scripting (XSS) or similar injection-style vulnerability that allows an attacker to gain unauthorized access to critical data or perform unauthorized updates and deletions. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Knowledge Management 12.1.1, 12.1.2, 12.1.3

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-17: patched: Released as part of Oracle January 2017 Critical Patch Update

References

Related threats