Junglewise Threat Intelligence

CVE-2017-3431: Oracle One-to-One Fulfillment unauthorized data access in User Interface

CVE-2017-3431 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle One-To-One Fulfillment. Vendors: Oracle.

Executive brief

A vulnerability exists in the user interface of Oracle One-to-One Fulfillment, a component of the Oracle E-Business Suite used for managing high-volume personalized communications. An attacker could trick a user into performing an action that allows the attacker to view or modify sensitive business data. This could lead to unauthorized access to critical information or the alteration of records within the fulfillment system.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle One-to-One Fulfillment within the Oracle E-Business Suite. It is an unauthenticated, network-based attack vector (HTTP) that requires human interaction from a victim (User Interaction: Required). The vulnerability has a 'Changed' scope, meaning an exploit can impact components beyond the immediate fulfillment module. Successful exploitation can result in unauthorized read access to all accessible data (Confidentiality: High) and unauthorized update or delete access to some data (Integrity: Low). The issue is addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle One-to-One Fulfillment 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: advisory: Initial publication of the vulnerability details.
  • 2017-01-27: patched: Oracle released patches as part of the January 2017 Critical Patch Update.

References

Related threats