Junglewise Threat Intelligence

CVE-2017-3368: Oracle iStore unauthorized data access in Address Book

CVE-2017-3368 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Istore. Vendors: Oracle.

Executive brief

A vulnerability exists in the Address Book subcomponent of Oracle iStore, an e-commerce platform within the Oracle E-Business Suite. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive customer data or modify existing records. Successful exploitation requires a legitimate user to interact with a malicious link or page, which could lead to a significant breach of data confidentiality and integrity across the platform.

Technical details

This vulnerability affects the Address Book subcomponent of Oracle iStore within Oracle E-Business Suite. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the application. The attack requires human interaction from a person other than the attacker (User Interaction: Required) and has a 'Changed' Scope, meaning the impact can extend beyond the iStore component to other parts of the E-Business Suite. Successful exploitation can result in unauthorized read access to all iStore data and unauthorized update, insert, or delete access to a subset of that data. The vulnerability is addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle iStore 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats