Junglewise Threat Intelligence

CVE-2017-3418: Oracle E-Business Suite CRM Technical Foundation Vulnerability in User Interface

CVE-2017-3418 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Customer Relationship Management Technical Foundation, Oracle E-Business Suite CRM Technical Foundation. Vendors: Oracle.

Executive brief

A vulnerability in the Oracle E-Business Suite CRM Technical Foundation could allow an unauthorized person to access or modify sensitive business data. This component is used to manage customer relationships and business operations; an exploit could lead to the theft of customer information or unauthorized changes to records. For an attack to succeed, a legitimate user must interact with a malicious link or webpage provided by the attacker.

Technical details

This vulnerability exists in the User Interface subcomponent of the Oracle CRM Technical Foundation within Oracle E-Business Suite version 12.1.3. It is an unauthenticated, network-based attack vector via HTTP that requires user interaction (UI:R) to succeed. The vulnerability has a 'Changed' scope (S:C), meaning an exploit can impact components beyond the CRM Technical Foundation itself. Successful exploitation can result in unauthorized read access to all accessible data and unauthorized update, insert, or delete access to a subset of that data. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle E-Business Suite CRM Technical Foundation 12.1.3

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-27: patched: Addressed in Oracle January 2017 Critical Patch Update

References

Related threats