Junglewise Threat Intelligence

CVE-2017-3430: Oracle E-Business Suite One-to-One Fulfillment security bypass in User Interface

CVE-2017-3430 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle One-To-One Fulfillment. Vendors: Oracle.

Executive brief

A vulnerability exists in the user interface of Oracle One-to-One Fulfillment, a component of the Oracle E-Business Suite used for managing high-volume customer communications. An attacker could trick a user into performing an action that allows the attacker to view, modify, or delete sensitive business data. This could lead to a significant breach of confidentiality and unauthorized changes to customer fulfillment records.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle One-to-One Fulfillment within Oracle E-Business Suite. It is an unauthenticated, network-based attack vector (HTTP) that requires human interaction from a person other than the attacker (UI:R). The vulnerability has a 'Changed' scope (S:C), meaning a successful exploit can impact components beyond the immediate fulfillment module. Attackers can achieve high confidentiality impact, allowing for the unauthorized access of all accessible data, and low integrity impact, allowing for unauthorized updates or deletions of certain data. The vulnerability is addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle One-to-One Fulfillment 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed: Initial NVD publication
  • 2017-01-27: advisory: Oracle Critical Patch Update issued

References

Related threats