Junglewise Threat Intelligence

CVE-2017-3369: Oracle iSupport vulnerability in User Interface

CVE-2017-3369 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Isupport. Vendors: Oracle.

Executive brief

A vulnerability exists in the user interface of Oracle iSupport, a customer service and support module within the Oracle E-Business Suite. An attacker could trick a legitimate user into performing an action that allows the attacker to view, modify, or delete sensitive support data. This could lead to a significant breach of customer information or unauthorized changes to support records.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle iSupport in Oracle E-Business Suite versions 12.1.1, 12.1.2, and 12.1.3. It is an unauthenticated, network-based attack delivered via HTTP. The exploit requires human interaction from a person other than the attacker (UI:R), suggesting a Cross-Site Scripting (XSS) or similar request forgery class of vulnerability. A successful exploit has a 'Changed' scope (S:C), meaning the impact can extend beyond iSupport to other components of the E-Business Suite. Attackers can achieve high confidentiality impact and low integrity impact, allowing for the unauthorized viewing of all accessible data and the modification or deletion of some data.

Affected products

  • Oracle iSupport 12.1.1, 12.1.2, 12.1.3

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-17: patched: Oracle Critical Patch Update (CPU) released

References

Related threats