Junglewise Threat Intelligence

CVE-2017-3435: Oracle E-Business Suite One-to-One Fulfillment UI data compromise

CVE-2017-3435 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle One-To-One Fulfillment. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle One-to-One Fulfillment component of the Oracle E-Business Suite, which is used by organizations to manage high-volume personalized communications. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify existing records. Successful exploitation requires a legitimate user to interact with a malicious link or page, potentially leading to a significant breach of data confidentiality and integrity across the suite.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle One-to-One Fulfillment within Oracle E-Business Suite versions 12.1.x and 12.2.x. It is an easily exploitable flaw that allows an unauthenticated remote attacker to compromise the system over HTTP. The attack requires human interaction from a person other than the attacker (UI:R) and results in a scope change (S:C), meaning the impact can extend beyond the immediate component to other parts of the E-Business Suite. Exploitation can lead to unauthorized read access to all accessible data and unauthorized update, insert, or delete access to a subset of data. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle One-to-One Fulfillment 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-17: patched: Addressed in Oracle January 2017 Critical Patch Update

References

Related threats