Junglewise Threat Intelligence

CVE-2017-3425: Oracle E-Business Suite One-to-One Fulfillment Security Bypass in UI

CVE-2017-3425 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle One-To-One Fulfillment. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle One-to-One Fulfillment component of the Oracle E-Business Suite, which is used for managing high-volume personalized communications. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify existing records. Successful exploitation requires a legitimate user to interact with a malicious link or page, potentially allowing the attacker to compromise the application and impact connected systems.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle One-to-One Fulfillment within Oracle E-Business Suite. It is an unauthenticated, network-based attack vector (HTTP) that requires human interaction from a person other than the attacker (UI:R). The vulnerability has a 'Changed' scope (S:C), meaning an exploit can impact components beyond the immediate One-to-One Fulfillment environment. Attackers can achieve unauthorized access to all accessible data (Confidentiality: High) and perform unauthorized updates or deletions of some data (Integrity: Low). Affected versions include 12.1.1 through 12.2.6.

Affected products

  • Oracle One-to-One Fulfillment 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update (CPU) released

References

Related threats