Junglewise Threat Intelligence

CVE-2017-3366: Oracle Knowledge Management vulnerability in User Interface

CVE-2017-3366 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Knowledge Management. Vendors: Oracle.

Executive brief

A vulnerability exists in the User Interface of Oracle Knowledge Management, a component of the Oracle E-Business Suite used for managing corporate information and support resources. An unauthenticated attacker can exploit this flaw to gain unauthorized access to sensitive data or modify existing records. Successful exploitation requires a legitimate user to perform a specific action, such as clicking a malicious link, and could potentially allow the attacker to impact other integrated business systems.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Knowledge Management within Oracle E-Business Suite. It is an unauthenticated, network-based attack vector (HTTP) that requires user interaction (UI:R) to succeed. The vulnerability has a 'Changed' scope (S:C), meaning an exploit can impact components beyond the immediate Knowledge Management environment. Attackers can achieve high confidentiality impact, gaining access to critical data, and low integrity impact, allowing for unauthorized updates or deletions of some data. The issue is addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle Knowledge Management 12.1.1, 12.1.2, 12.1.3

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-17: patched: Addressed in Oracle Critical Patch Update (CPU) January 2017

References

Related threats