Executive brief
A vulnerability exists in the User Interface component of Oracle E-Business Suite's CRM Technical Foundation. This flaw allows an unauthenticated attacker to potentially gain unauthorized access to sensitive business data or modify records. To be successful, the attack requires a legitimate user to interact with a malicious link or page, which could lead to a compromise of the CRM system and connected business applications.
Technical details
This vulnerability affects the User Interface subcomponent of the Oracle CRM Technical Foundation in Oracle E-Business Suite version 12.1.3. It is classified as an easily exploitable flaw that can be triggered by an unauthenticated attacker over the network via HTTP. The exploit requires human interaction from a person other than the attacker (UI:R) and results in a Scope change (S:C), meaning the impact can extend beyond the CRM Technical Foundation to other integrated products. Successful exploitation can lead to unauthorized access to all accessible data (Confidentiality: High) and unauthorized modification or deletion of some data (Integrity: Low). The vulnerability was addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle E-Business Suite 12.1.3
Timeline
- 2017-01-27: advisory: Initial disclosure by Oracle
- 2017-01-27: patched: Fix released in January 2017 Critical Patch Update