Junglewise Threat Intelligence

CVE-2017-3417: Oracle E-Business Suite Universal Work Queue unauthorized data access

CVE-2017-3417 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle E-Business Suite Universal Work Queue. Vendors: Oracle.

Executive brief

A vulnerability in the Oracle E-Business Suite's Universal Work Queue component could allow an unauthorized person to access or modify sensitive business data. The Universal Work Queue is a central interface used by employees to manage tasks and workflows across the enterprise. An attacker could exploit this by tricking a legitimate user into performing an action, potentially leading to the theft of critical information or unauthorized changes to business records.

Technical details

This vulnerability exists in the User Interface subcomponent of the Oracle Universal Work Queue within Oracle E-Business Suite. It is classified as an 'easily exploitable' flaw that allows an unauthenticated attacker with network access via HTTP to compromise the component. The exploit requires human interaction from a user other than the attacker (UI:R) and has a 'Changed' scope (S:C), meaning the impact can extend beyond the Universal Work Queue to other products. Successful exploitation can result in unauthorized read access to all accessible data and unauthorized update, insert, or delete access to a subset of that data. The vulnerability is addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle E-Business Suite Universal Work Queue 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-17: patched: Oracle January 2017 Critical Patch Update released

References

Related threats