Junglewise Threat Intelligence

CVE-2017-3424: Oracle E-Business Suite vulnerability in One-to-One Fulfillment UI

CVE-2017-3424 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle One-To-One Fulfillment. Vendors: Oracle.

Executive brief

A vulnerability exists in the user interface of Oracle One-to-One Fulfillment, a component of the Oracle E-Business Suite used for managing high-volume customer communications. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify existing records. Successful exploitation requires a legitimate user to interact with a malicious link or page, which could lead to a broader compromise of connected business systems.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle One-to-One Fulfillment within Oracle E-Business Suite. It is classified as an 'easily exploitable' flaw that allows an unauthenticated remote attacker to compromise the system via HTTP. The exploit requires user interaction (UI:R) and has a 'Changed' scope (S:C), suggesting it may be a Cross-Site Scripting (XSS) or similar injection vulnerability that allows an attacker to impact components beyond the immediate application. Successful exploitation can lead to high confidentiality impacts and partial integrity impacts, allowing unauthorized viewing of all data or modification of certain records. Affected versions include 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle One-to-One Fulfillment 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published
  • 2017-01-27: patched

References

Related threats