Junglewise Threat Intelligence

CVE-2017-3415: Oracle Universal Work Queue unauthorized data access in User Interface

CVE-2017-3415 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Universal Work Queue. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Universal Work Queue component of the Oracle E-Business Suite, which is used by organizations to manage and distribute tasks across different departments. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify existing records. Successful exploitation requires a legitimate user to perform a specific action, such as clicking a malicious link, and could potentially allow the attacker to impact other integrated business systems.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Universal Work Queue within Oracle E-Business Suite. It is an unauthenticated, network-based attack vector via HTTP. The vulnerability has a CVSS 3.0 base score of 8.2, characterized by high confidentiality impact and low integrity impact. A key precondition is human interaction from a person other than the attacker (UI:R). The 'Scope' metric is changed (S:C), indicating that a successful exploit can impact components beyond the immediate security scope of the Universal Work Queue. Attackers can achieve unauthorized access to all accessible data or perform unauthorized updates, inserts, or deletes on a subset of data. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Universal Work Queue 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: patched: Fixed in Oracle Critical Patch Update January 2017

References

Related threats