Junglewise Threat Intelligence

CVE-2017-3370: Oracle iSupport vulnerability in User Interface

CVE-2017-3370 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Isupport. Vendors: Oracle.

Executive brief

A vulnerability exists in the User Interface of Oracle iSupport, a component of the Oracle E-Business Suite used for customer service and support management. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify existing records. Successful exploitation requires a legitimate user to perform an action, such as clicking a malicious link, and could potentially allow the attacker to impact other integrated Oracle products.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle iSupport in Oracle E-Business Suite versions 12.1.1, 12.1.2, and 12.1.3. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the application. The attack requires human interaction from a person other than the attacker (UI:R) and has a 'Changed' scope (S:C), meaning the impact can extend beyond the iSupport component to other products. Successful exploitation can result in unauthorized high-impact confidentiality breaches and low-impact integrity violations, such as unauthorized data updates or deletions. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle iSupport 12.1.1, 12.1.2, 12.1.3

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-17: patched: Released as part of Oracle Critical Patch Update Advisory - January 2017

References

Related threats