Executive brief
A vulnerability exists in the user interface of Oracle One-to-One Fulfillment, a component of the Oracle E-Business Suite used for managing high-volume personalized communications. An attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify existing records. Successful exploitation requires a legitimate user to interact with a malicious link or page, which could lead to a broader compromise of connected systems.
Technical details
This vulnerability in the Oracle One-to-One Fulfillment User Interface (part of Oracle E-Business Suite) is classified as 'easily exploitable' by the vendor. It allows an unauthenticated remote attacker to target the system over HTTP. The exploit requires human interaction from a person other than the attacker (UI:R), suggesting a Cross-Site Scripting (XSS) or similar client-side injection flaw. A successful attack results in a 'Changed' scope (S:C), meaning the impact can extend beyond the One-to-One Fulfillment component to other parts of the E-Business Suite environment. Attackers can achieve high confidentiality impact and partial integrity impact, allowing for the theft of sensitive data or unauthorized data manipulation. Fixes were released as part of the Oracle Critical Patch Update (CPU) in January 2017.
Affected products
- Oracle One-to-One Fulfillment 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-17: patched: Addressed in Oracle Critical Patch Update January 2017