Executive brief
A vulnerability exists in the User Interface of Oracle iSupport, a customer service and support module within the Oracle E-Business Suite. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive customer data or modify existing records. Successful exploitation requires a legitimate user to interact with a malicious link or page, which could lead to a significant breach of data confidentiality and integrity across the support platform.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle iSupport versions 12.1.1, 12.1.2, and 12.1.3. It is classified as an easily exploitable flaw that can be triggered by an unauthenticated attacker over the network via HTTP. The exploit requires human interaction from a person other than the attacker (UI:R) and has a 'Changed' Scope (S:C), meaning the impact can extend beyond the iSupport component itself. Successful exploitation allows for unauthorized high-impact read access to data and low-impact unauthorized modification, insertion, or deletion of data. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle iSupport 12.1.1, 12.1.2, 12.1.3
Timeline
- 2017-01-27: advisory: NVD publication date
- 2017-01-17: patched: Released as part of Oracle Critical Patch Update (CPU) January 2017