Executive brief
A vulnerability exists in the User Interface component of Oracle's CRM Technical Foundation, a core part of the Oracle E-Business Suite used for managing customer relationships. An unauthenticated attacker could exploit this flaw by tricking a legitimate user into performing a specific action, such as clicking a malicious link. If successful, the attacker could gain unauthorized access to sensitive business data or modify records, potentially impacting other integrated Oracle products.
Technical details
This vulnerability resides in the User Interface subcomponent of the Oracle CRM Technical Foundation within Oracle E-Business Suite version 12.1.3. It is classified as an 'easily exploitable' flaw that requires network access via HTTP and user interaction from a person other than the attacker (UI:R). The vulnerability has a 'Scope' impact (S:C), meaning an exploit can affect components beyond the CRM Technical Foundation itself. Successful exploitation allows an unauthenticated attacker to achieve high confidentiality impact (unauthorized access to all data) and low integrity impact (unauthorized update, insert, or delete access to some data). Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle E-Business Suite (CRM Technical Foundation) 12.1.3
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-17: patched: Addressed in Oracle January 2017 Critical Patch Update