Executive brief
A vulnerability exists in the Oracle One-to-One Fulfillment component of the Oracle E-Business Suite, which manages high-volume personalized communications. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify existing records. This attack requires a legitimate user to perform an action, such as clicking a malicious link, and could potentially allow the attacker to impact other connected systems.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle One-to-One Fulfillment within Oracle E-Business Suite. It is an unauthenticated, network-based vulnerability (HTTP) that requires human interaction from a person other than the attacker (UI:R). The CVSS vector indicates a Scope change (S:C), suggesting that an exploit could impact components beyond the immediate One-to-One Fulfillment environment. Successful exploitation can result in high confidentiality impact (unauthorized access to all accessible data) and low integrity impact (unauthorized update, insert, or delete access to some data). The vulnerability was addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle One-to-One Fulfillment (E-Business Suite) 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-17: patched: Addressed in Oracle January 2017 Critical Patch Update