Executive brief
A vulnerability exists in the User Interface of Oracle Knowledge Management, a component of the Oracle E-Business Suite used for managing corporate information and support resources. An unauthenticated attacker could trick a legitimate user into performing an action that allows the attacker to view or modify sensitive data. This could lead to a significant breach of confidentiality and unauthorized changes to business information across the suite.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Knowledge Management within Oracle E-Business Suite versions 12.1.1, 12.1.2, and 12.1.3. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the component. The exploit requires human interaction from a person other than the attacker (UI:R) and has a 'Changed' scope (S:C), meaning the impact can extend beyond the Knowledge Management component to other parts of the E-Business Suite. Successful exploitation can result in unauthorized access to all accessible data or unauthorized modification (update, insert, or delete) of some data. The vulnerability was addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle Knowledge Management 12.1.1, 12.1.2, 12.1.3
Timeline
- 2017-01-27: advisory: NVD publication date
- 2017-01-17: patched: Released as part of Oracle Critical Patch Update (CPU) January 2017