Junglewise Threat Intelligence

CVE-2017-3367: Oracle Knowledge Management vulnerability in User Interface

CVE-2017-3367 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Knowledge Management. Vendors: Oracle.

Executive brief

A vulnerability exists in the User Interface of Oracle Knowledge Management, a component of the Oracle E-Business Suite used for managing corporate information and self-service support. An attacker can exploit this flaw to gain unauthorized access to sensitive data or modify information within the system. This could lead to the exposure of proprietary knowledge bases or the corruption of critical business records, though it requires a legitimate user to perform an action like clicking a malicious link.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Knowledge Management within Oracle E-Business Suite versions 12.1.1, 12.1.2, and 12.1.3. It is an unauthenticated, network-based attack delivered via HTTP. The exploit requires human interaction (UI:R) from a person other than the attacker, suggesting a Cross-Site Scripting (XSS) or similar client-side injection flaw. Successful exploitation has a high impact on confidentiality and a low impact on integrity, with a 'Changed' scope (S:C), meaning the attack can impact components beyond the Knowledge Management module itself. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Knowledge Management 12.1.1, 12.1.2, 12.1.3

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update (CPU) January 2017 released.

References

Related threats