Junglewise Threat Intelligence

CVE-2017-3372: Oracle E-Business Suite data compromise in Interaction Blending

CVE-2017-3372 · Severity: high · CVSS 8.2 · Published 2017-01-27

Vendors: Oracle.

Executive brief

A vulnerability exists in the Interaction Blending component of Oracle E-Business Suite, which manages multi-channel communication for contact centers. An attacker can exploit this flaw to gain unauthorized access to sensitive business data or modify existing records. Successful exploitation requires a legitimate user to perform a specific action, such as clicking a malicious link, and could potentially allow the attacker to impact other connected systems.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Interaction Blending within Oracle E-Business Suite. It is an unauthenticated, network-based attack vector (HTTP) that requires human interaction from a person other than the attacker (UI:R). The vulnerability has a 'Changed' scope (S:C), meaning an exploit can impact components beyond the immediate security scope of Interaction Blending. Attackers can achieve unauthorized access to critical data or complete access to all accessible data, as well as unauthorized update, insert, or delete capabilities for some data. The issue is addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle E-Business Suite (Interaction Blending) 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-17: patched: Oracle January 2017 Critical Patch Update released

References