Junglewise Threat Intelligence

CVE-2017-3429: Oracle One-to-One Fulfillment vulnerability in User Interface

CVE-2017-3429 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle One-To-One Fulfillment. Vendors: Oracle.

Executive brief

A vulnerability exists in the user interface of Oracle One-to-One Fulfillment, a component of the Oracle E-Business Suite used for managing high-volume customer communications. An attacker could trick a user into performing an action that allows the attacker to view or modify sensitive business data. This could lead to unauthorized access to critical information or the alteration of records within the fulfillment system.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle One-to-One Fulfillment within Oracle E-Business Suite. It is an unauthenticated, network-based attack vector via HTTP that requires human interaction from a person other than the attacker (UI:R). The vulnerability has a high confidentiality impact and a low integrity impact, with a Scope change (S:C) indicating that an exploit could impact components beyond the immediate fulfillment module. Attackers can gain unauthorized access to critical data or perform unauthorized updates, inserts, or deletes on a subset of accessible data. The issue is addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle One-to-One Fulfillment 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: advisory: Initial disclosure by Oracle
  • 2017-01-27: disclosed

References

Related threats