Junglewise Threat Intelligence

CVE-2017-3416: Oracle E-Business Suite Universal Work Queue unauthorized data access

CVE-2017-3416 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Universal Work Queue. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Universal Work Queue, a component of the Oracle E-Business Suite used for managing tasks and workflows. An unauthenticated attacker could trick a user into performing an action that allows the attacker to view or modify sensitive business data. This could lead to unauthorized access to critical information or the alteration of work records, potentially impacting other integrated business systems.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Universal Work Queue within Oracle E-Business Suite. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the component. The exploit requires human interaction from a person other than the attacker (UI:R) and has a 'Changed' scope (S:C), meaning the impact can extend beyond the Universal Work Queue to other products. Successful exploitation can result in unauthorized read access to all accessible data and unauthorized update, insert, or delete access to a subset of that data. The vulnerability was addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle Universal Work Queue 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats