Executive brief
A vulnerability exists in the User Interface of Oracle Knowledge Management, a component of the Oracle E-Business Suite used for managing corporate information and self-service support. An attacker can exploit this flaw to gain unauthorized access to sensitive data or modify information within the system. This could lead to the exposure of proprietary knowledge bases or the corruption of critical business records, though it requires a legitimate user to perform an action like clicking a malicious link.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Knowledge Management within Oracle E-Business Suite versions 12.1.1, 12.1.2, and 12.1.3. It is an unauthenticated, network-based attack delivered via HTTP. The exploit requires human interaction (UI:R) from a person other than the attacker, suggesting a Cross-Site Scripting (XSS) or similar client-side injection flaw. Successful exploitation has a high impact on confidentiality and a low impact on integrity, with a 'Changed' scope (S:C), meaning the attack can impact components beyond the Knowledge Management module itself. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle Knowledge Management 12.1.1, 12.1.2, 12.1.3
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update (CPU) January 2017 released.