Junglewise Threat Intelligence

CVE-2017-3422: Oracle E-Business Suite One-to-One Fulfillment UI vulnerability

CVE-2017-3422 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle One-To-One Fulfillment. Vendors: Oracle.

Executive brief

A vulnerability exists in the User Interface of Oracle One-to-One Fulfillment, a component of the Oracle E-Business Suite used for managing high-volume customer communications. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify existing records. Successful exploitation requires a legitimate user to interact with a malicious link or page, which could lead to a significant breach of data integrity and confidentiality across the platform.

Technical details

A vulnerability in the User Interface subcomponent of Oracle One-to-One Fulfillment (Oracle E-Business Suite) allows unauthenticated attackers with network access via HTTP to compromise the system. The vulnerability is characterized by a CVSS 3.0 score of 8.2, indicating high confidentiality impact and low integrity impact. Exploitation requires human interaction from a person other than the attacker (UI:R) and has a 'Changed' scope (S:C), meaning the impact can extend beyond the vulnerable component to other parts of the E-Business Suite. Attackers can achieve unauthorized access to all accessible data or perform unauthorized updates, inserts, or deletions of certain data. Affected versions include 12.1.1-12.1.3 and 12.2.3-12.2.6. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle One-to-One Fulfillment (E-Business Suite) 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-17: patched: Addressed in Oracle January 2017 Critical Patch Update

References

Related threats